Anonymous
2026-06-29 21:22:19
(2 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-29 19:20:24
(4 hours ago)
(upload_shell) srv104 Shell upload 173.239.196.190 (BD/Bangladesh/-): 1 in the last 3600 secs; Ports ...
show more
(upload_shell) srv104 Shell upload 173.239.196.190 (BD/Bangladesh/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 18:10:52
(5 hours ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.190 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 14:10:46.566868 2026] [security2:error] [pid 28746:tid 28746] [client 173.239.196.190:59633] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||f40ph.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "f40ph.org"] [uri "/images/stories/themes.php"] [unique_id "akK1JpVf6tK6LOvpw7-pjAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-06-29 18:02:47
(5 hours ago)
wordpress scan on wellspr.ing/blog/wp-admin/about.php โ WellSpr.ing/NetSentinel civic-AI security la ...
show more
wordpress scan on wellspr.ing/blog/wp-admin/about.php โ WellSpr.ing/NetSentinel civic-AI security layer
show less
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-29 09:22:26
(14 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-29 08:23:49
(15 hours ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.190 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 04:23:43.680748 2026] [security2:error] [pid 3318:tid 3318] [client 173.239.196.190:22497] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||solidthought.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "solidthought.com"] [uri "/images/stories/themes.php"] [unique_id "akIrj1MUYkfF10VKEh9r7QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-29 04:56:29
(18 hours ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-195)
Hacking
๐ณ๐ฑ
Site.eu
2026-06-29 02:40:19
(20 hours ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ช
cmbplf
2026-06-28 08:02:27
(1 day ago)
2.231 requests from abuseipdb.com blacklisted IP (1yr1mo2w)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-27 16:09:29
(2 days ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.190 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 12:09:23.944101 2026] [security2:error] [pid 13462:tid 13462] [client 173.239.196.190:35273] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||anxo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "anxo.net"] [uri "/images/stories/themes.php"] [unique_id "aj_1sxYDodk3oDnOJ44s2QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-27 13:27:43
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
masterguru
2026-06-27 12:32:25
(2 days ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-201)
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-06-27 05:15:56
(2 days ago)
2 attacks on ACME URLs:
GET /.well-known/acme-challenge/gecko-old.php HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 01:16:18
(2 days ago)
(mod_security) mod_security (id:240000) triggered by 173.239.196.190 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 173.239.196.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 21:16:11.387525 2026] [security2:error] [pid 31989:tid 31995] [client 173.239.196.190:25703] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||rudimentseq.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "rudimentseq.com"] [uri "/images/stories/themes.php"] [unique_id "aj8kWwVg3LUjtmM3N5Y37wAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-26 20:48:32
(3 days ago)
Web attack/malicious scanning detected
Web App Attack