๐บ๐ธ
ke1v3y_OTU
2026-07-09 06:11:01
(2 months ago)
SQL injection attempt against a public web endpoint.
SQL Injection
Web App Attack
๐บ๐ธ
MPL
2026-05-01 19:05:23
(4 months ago)
tcp/80 (2 or more attempts)
Port Scan
Anonymous
2026-03-28 03:05:33
(5 months ago)
Blocked: Reason='Possible SQL injection activity (14/60 min)'; Requests=14
SQL Injection
๐ฎ๐ฉ
Burayot
2026-03-28 02:02:53
(5 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.24.11.140 (AT/Austria/unn-185-24 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.24.11.140 (AT/Austria/unn-185-24-11-140.datapacket.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 02:01:05
(5 months ago)
(mod_security) mod_security (id:218580) triggered by 185.24.11.140 (unn-185-24-11-140.datapacket.com ...
show more
(mod_security) mod_security (id:218580) triggered by 185.24.11.140 (unn-185-24-11-140.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 22:00:57.695049 2026] [security2:error] [pid 7420:tid 7431] [client 185.24.11.140:56859] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:start. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||uoexpanse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "uoexpanse.com"] [uri "/forums/viewtopic.php"] [unique_id "acc2WQ5ntStMfWC4ptAsngAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-25 17:42:53
(5 months ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-03-25 05:14:50
(5 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /bibliography/4733565 (Rule ID: 941100) - XSS Attack Detected via libinjection
show less
Web App Attack
SQL Injection
๐ฎ๐ฉ
penjaga BRIN
2026-03-24 21:04:27
(5 months ago)
SQL injection attempt
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-03-24 20:51:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 185.24.11.140 (unn-185-24-11-140.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 185.24.11.140 (unn-185-24-11-140.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 16:51:32.439751 2026] [security2:error] [pid 1254873:tid 1254873] [client 185.24.11.140:62166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psdinnersready.com"] [uri "/.env"] [unique_id "acL5VNO3sRxnqHXW24d6XwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 20:45:29
(5 months ago)
(mod_security) mod_security (id:211190) triggered by 185.24.11.140 (unn-185-24-11-140.datapacket.com ...
show more
(mod_security) mod_security (id:211190) triggered by 185.24.11.140 (unn-185-24-11-140.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 16:45:24.500266 2026] [security2:error] [pid 1232:tid 1250] [client 185.24.11.140:57603] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||seips.org|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /viewitem.php?ID=403&__waf_test__=%27+OR+%271%27%3D%271%27+UNION+SELECT+NULL%2C%27%3Cscript%3Ealert%281%29%3C%2Fscript%3E%27%2Ctable_name+FROM+information_schema.tables+WHERE+2%3E1--%2F%2A%2A%2F%3B+EXEC+xp_cmdshell%28%27cat+%2Fetc%2Fpasswd%27%29%23"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seips.org"] [uri "/viewitem.php"] [unique_id "acGmZIAKMwFCgvbdq2kYAAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
fortypoundhead
2026-03-13 13:46:24
(6 months ago)
SQL Injection Attempt
SQL Injection
Web App Attack
Anonymous
2026-03-13 13:28:35
(6 months ago)
185.24.11.140 - - [13/Mar/2026:13:28:34 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1% ...
show more
185.24.11.140 - - [13/Mar/2026:13:28:34 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1" 307 5984 "https://atari-forum.com/viewtopic.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO))," "-"
...
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-03-11 06:28:40
(6 months ago)
(mod_security) mod_security (id:218580) triggered by 185.24.11.140 (unn-185-24-11-140.datapacket.com ...
show more
(mod_security) mod_security (id:218580) triggered by 185.24.11.140 (unn-185-24-11-140.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 02:28:34.486921 2026] [security2:error] [pid 1214:tid 1214] [client 185.24.11.140:57450] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:ascDesc. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||www.3905ccn.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "www.3905ccn.org"] [uri "/awardsByCallsign.php"] [unique_id "abELkviUKqVXveEaQmEq5QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-10 20:58:34
(6 months ago)
185.24.11.140 - - [10/Mar/2026:20:58:33 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1% ...
show more
185.24.11.140 - - [10/Mar/2026:20:58:33 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1" 307 709 "https://www.atari-forum.com/viewtopic.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO))," "-"
...
show less
SQL Injection
๐จ๐ญ
backslash
2025-12-16 07:55:08
(8 months ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot