๐ง๐ช
voormedia
2026-02-09 05:09:22
(4 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ช๐ธ
el-brujo
2026-02-05 13:35:47
(4 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0 Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: POST Timestamp: 2026-02-05T13:35:47Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-16 06:19:35
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฎ๐ฉ
Burayot
2025-12-30 03:35:44
(5 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 193.56.20.55 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 193.56.20.55 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
nowyouknow
2025-12-19 03:44:41
(5 months ago)
(From [email protected] ) Hey Team,
I typed your main service keywords into Google today, ...
show more
(From [email protected] ) Hey Team,
I typed your main service keywords into Google today, and I noticed something frustrating. Your website is professionally designed, but itโs buried on Page 2.
Meanwhile, 2 or 3 of your direct competitors, who frankly have weaker websites than youโare sitting at the top of Page 1.
They are effectively "stealing" leads that were looking for you. They aren't better than you; they just have better SEO signals.
Iโve already analyzed exactly what they are doing differently.
If you want to see the comparison report, just reply "Yes" and Iโll send it over.
Cheers,
QIK
show less
Phishing
Web Spam
๐บ๐ธ
COMPLEX
2025-11-29 03:58:38
(6 months ago)
Triggered Cloudflare WAF (l7ddos) from US.
Action taken: BLOCK
ASN: 26548 (PUREVOLTAGE-INC)
Protocol ...
show more
Triggered Cloudflare WAF (l7ddos) from US.
Action taken: BLOCK
ASN: 26548 (PUREVOLTAGE-INC)
Protocol: HTTP/2 (GET method)
Endpoint: /
show less
DDoS Attack
Bad Web Bot
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-29 00:42:58
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-08 16:36:22
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 193.56.20.55 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 193.56.20.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 11:36:15.060960 2025] [security2:error] [pid 30842:tid 30842] [client 193.56.20.55:57195] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tekbit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tekbit.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ9xf-NEABEKJGhtHX0nYAAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
licjperezl
2025-06-10 19:10:44
(1 year ago)
Ataque de diccionario o DDoS en nuestros servicios en linea
Brute-Force
Anonymous
2025-01-27 14:15:00
(1 year ago)
Used in a distributed login attack
Brute-Force
Anonymous
2024-12-20 00:56:50
(1 year ago)
Attempted brute force login to web vpn
Hacking
Brute-Force
Anonymous
2024-10-08 16:35:09
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
๐จ๐ฆ
wil.com
2024-09-24 04:48:39
(1 year ago)
GlobalProtect login attempts with user ehurley.
VPN IP
Brute-Force
๐ฉ๐ช
conseilgouz
2024-07-20 17:33:51
(1 year ago)
coe-12 : Block return, carriage return, ... characters=>/en/component/weblinks/weblink/52-astroid-de ...
show more
coe-12 : Block return, carriage return, ... characters=>/en/component/weblinks/weblink/52-astroid-de-joomdev-2?catid=14&Itemid=305%27&task=weblink.g...(')
show less
Hacking
๐บ๐ธ
TPI-Abuse
2024-07-15 22:45:31
(1 year ago)
(mod_security) mod_security (id:210410) triggered by 193.56.20.55 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210410) triggered by 193.56.20.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 15 18:45:25.753413 2024] [security2:error] [pid 7270] [client 193.56.20.55:35455] [client 193.56.20.55] ModSecurity: Access denied with code 403 (phase 2). Found 1 byte(s) in ARGS:action outside range: 1-255. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "95"] [id "210410"] [rev "4"] [msg "COMODO WAF: Invalid character in request||www.oualierealty.com|F|3"] [data "ARGS:action=listingview<!' )) AND 1=1 (( ' -- rgzd\\x00"] [severity "ERROR"] [tag "CWAF"] [tag "Protocol"] [hostname "www.oualierealty.com"] [uri "/index.php"] [unique_id "ZpWmhboSM2nMgS12MU6oNwAAAAE"], referer: http://www.coldwellbankerstkittsnevis.com/index.php?action=listingview%3C!%27%20))%20AND%201=1%20((%20%27%20--%20rgzd%00&listingID=88%3C!%27%20))%20AND%201=1%20((%20%27%20--%20rgzd%00
show less
Brute-Force
Bad Web Bot
Web App Attack