Anonymous
2026-06-14 09:10:09
(5 days ago)
Command Injection Exploit Sensor - HTTP (Request) - Variant 2
Hacking
๐ฉ๐ช
ghostwarriors
2026-05-31 08:50:29
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 06:03:43
(2 weeks ago)
(mod_security) mod_security (id:234930) triggered by 185.92.26.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:234930) triggered by 185.92.26.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 02:03:36.655170 2026] [security2:error] [pid 20058:tid 20154] [client 185.92.26.19:20845] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||twinsonderhoud.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "twinsonderhoud.nl"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ahvPONd4jOkKGlVFPVnQoAAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-05-31 05:47:50
(2 weeks ago)
Suricata: Alert - ET INFO Go-http-client User-Agent Observed Inbound
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-31 02:43:40
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ช
lightaffaire
2026-05-31 00:16:28
(2 weeks ago)
May 31 02:16:28 www.lightaffaire.com 185.92.26.19 - - [31/May/2026:02:16:28 +0200] "GET //alfa.php H ...
show more
May 31 02:16:28 www.lightaffaire.com 185.92.26.19 - - [31/May/2026:02:16:28 +0200] "GET //alfa.php HTTP/2.0" 403 0 "http://akt.social/alfa.php" "Go-http-client/2.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 11:01:48
(2 weeks ago)
(mod_security) mod_security (id:240000) triggered by 185.92.26.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 185.92.26.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 07:01:42.333875 2026] [security2:error] [pid 17577:tid 17577] [client 185.92.26.19:34611] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||cyber-matrix.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "cyber-matrix.org"] [uri "/images/stories/themes.php"] [unique_id "ahrDlv7ozKzAdtB7P7xnYAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-28 14:02:18
(3 weeks ago)
Web attack
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-05-23 21:51:12
(3 weeks ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-05-23 03:27:00
(3 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-05-22 20:54:29
(4 weeks ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-10 05:43:03
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 185.92.26.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 185.92.26.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 01:42:56.734436 2026] [security2:error] [pid 25263:tid 25286] [client 185.92.26.19:26695] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||joblackwell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "joblackwell.com"] [uri "/images/stories/themes.php"] [unique_id "agAa4HHWa3Sjhhos3_YajAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-05-10 03:49:06
(1 month ago)
Aggressive web search of vulnerable pages: /about/function.php /wp-includes/Requests/index.php /wp-i ...
show more
Aggressive web search of vulnerable pages: /about/function.php /wp-includes/Requests/index.php /wp-includes/ID3/about.php/wp-content/x/index.ph ...
show less
Web App Attack
๐บ๐ธ
myagent.site
2026-03-28 14:43:03
(2 months ago)
Blocking for trying to access an exploit file: //style.php
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-28 12:11:54
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 185.92.26.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 185.92.26.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 07:11:49.665957 2026] [security2:error] [pid 4724:tid 4724] [client 185.92.26.19:39447] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||saadeh.ws|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "saadeh.ws"] [uri "/wp-login.php"] [unique_id "aaLbhd6KssHuqaPG5AUJcgAAABk"], referer: https://saadeh.ws/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack