๐บ๐ธ
BlueStem123
2026-08-17 16:00:31
(5 days ago)
Automated bot traffic with anomalous request patterns. Source produced sustained scanning activity e ...
show more
Automated bot traffic with anomalous request patterns. Source produced sustained scanning activity exceeding 100 requests within a 60-minute window.
show less
Bad Web Bot
๐ซ๐ท
dynamix
2026-08-16 17:22:52
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-16 17:10:09
(6 days ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Site.eu
2026-08-16 10:47:21
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
hpatteri
2026-08-15 23:00:00
(1 week ago)
Automated exploit path scanning โ 2468 requests to wp-admin/.env/.php/xmlrpc and similar paths, all ...
show more
Automated exploit path scanning โ 2468 requests to wp-admin/.env/.php/xmlrpc and similar paths, all blocked (HTTP 444). Observed 2026-08-15 UTC. Source: stocktrendz.app nginx log.
show less
Port Scan
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-09 22:39:53
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
masterguru
2026-08-09 12:04:46
(1 week ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-201)
Hacking
๐ณ๐ฑ
Site.eu
2026-08-08 11:21:40
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
โจ
2026-08-08 00:58:17
(2 weeks ago)
Domain : tomtaylormusic.co.uk
Rule : hack
2026-08-08 00:54:18 ***hidden-privacy*** GET /wp-content/p ...
show more
Domain : tomtaylormusic.co.uk
Rule : hack
2026-08-08 00:54:18 ***hidden-privacy*** GET /wp-content/plugins/atomlib.php - 80 - 173.239.196.135 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3 - tomtaylormusic.co.uk 301 0 0 466 228 156 - -
show less
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-08 00:26:47
(2 weeks ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.135 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 20:26:40.785245 2026] [security2:error] [pid 1312486:tid 1312486] [client 173.239.196.135:27787] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||flybits.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "flybits.org"] [uri "/images/stories/themes.php"] [unique_id "anZ3wAdiKZpNIYPJlw2l3wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 15:35:14
(2 weeks ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.135 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 11:35:09.284795 2026] [security2:error] [pid 264292:tid 264292] [client 173.239.196.135:33165] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||drstiso.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "drstiso.com"] [uri "/images/stories/themes.php"] [unique_id "anX7LRmozacqksllDjf64gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 13:34:36
(2 weeks ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.135 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 09:34:28.715259 2026] [security2:error] [pid 3153685:tid 3153701] [client 173.239.196.135:47511] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||vnbcares.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "vnbcares.com"] [uri "/images/stories/themes.php"] [unique_id "anXe5L31eXJjc0QrJD1JHwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-07 10:55:46
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฏ๐ต
Short-legs-Spider
2026-08-06 18:44:43
(2 weeks ago)
Test on existence
--
[07/Aug/2026:03:44:43 +0900] "GET /wp-content/uploads/wp.php HTTP/1.1" 403 76 ...
show more
Test on existence
--
[07/Aug/2026:03:44:43 +0900] "GET /wp-content/uploads/wp.php HTTP/1.1" 403 76 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
[07/Aug/2026:03:44:45 +0900] "GET /cgi-bin/class.api.php HTTP/1.1" 403 76 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
[07/Aug/2026:03:44:45 +0900] "GET /wp-content/cache/index.php HTTP/1.1" 403 76 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
[07/Aug/2026:03:44:45 +0900] "GET /wp-includes/certificates/about.php HTTP/1.1" 403 76 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
[07/Aug/2026:03:44:46 +0900] "GET /webdb.php HTTP/1.1" 403 76 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
...
show less
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-06 12:01:22
(2 weeks ago)
csagent: score 15.2: php 404 x3, 404 noise floor x3, webshell name x1; 2 domain(s) in 0s
Web App Attack