๐ฉ๐ช
raph
2026-06-25 11:29:41
(2 hours ago)
[SQL UNION SELECT] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(UNION%20| ...
show more
[SQL UNION SELECT] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(UNION%20|union%20|SELECT%20|select%20).* HTTP/1.1$
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-06-24 18:14:39
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org ...
show more
(mod_security) mod_security (id:225170) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 14:14:35.912606 2026] [security2:error] [pid 22569:tid 22569] [client 185.39.207.83:60086] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frelsburg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frelsburg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajwei7gp1kJ3WHZ_WkU5GQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 15:03:44
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org ...
show more
(mod_security) mod_security (id:210492) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 11:03:38.096244 2026] [security2:error] [pid 7063:tid 7063] [client 185.39.207.83:54386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.empire-fire.net"] [uri "/.git/config"] [unique_id "ajvxyne_FzxcQhY3iULXGQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-23 18:38:58
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 20:34:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org ...
show more
(mod_security) mod_security (id:210492) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 16:34:46.745012 2026] [security2:error] [pid 23870:tid 23870] [client 185.39.207.83:54162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.britanniapilates.com"] [uri "/.git/config"] [unique_id "ajmcZkLnMlC00wRWXEZ9fAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
ICS Labs
2026-06-22 15:42:02
(2 days ago)
ICS Labs identified 185.39.207.83 as a malicious indicator from threat intelligence.
DDoS Attack
Port Scan
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-22 02:52:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org ...
show more
(mod_security) mod_security (id:210492) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 22:52:47.762265 2026] [security2:error] [pid 4278:tid 4278] [client 185.39.207.83:46492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bigislandhawaiirealty.com"] [uri "/.git/config"] [unique_id "ajijf2Q5xaYkHhlamglKsQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-06-21 21:19:48
(3 days ago)
Known malicious PHP file or CMS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 15:16:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org ...
show more
(mod_security) mod_security (id:210492) triggered by 185.39.207.83 (vanzetti.osservatorionessuno.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 11:16:24.561741 2026] [security2:error] [pid 322:tid 322] [client 185.39.207.83:50422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wolfmachine.com"] [uri "/.git/config"] [unique_id "ajgASIdGcJPiTdK47rYVvQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-21 05:01:47
(4 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
COMAITE
2026-06-19 12:10:37
(6 days ago)
CMS (WordPress or Joomla) brute force attempt.
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-19 10:45:02
(6 days ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
LRob.fr
2026-06-19 08:15:03
(6 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-18 05:30:06
(1 week ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 05:17:58
(1 week ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=aidshep2019.gr; logs=/var/log/httpd/domains/aidshep2019.gr. ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=aidshep2019.gr; logs=/var/log/httpd/domains/aidshep2019.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack