๐ซ๐ท
dynamix
2026-05-23 21:28:57
(1 month ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 00:44:19
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 194.32.120.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 194.32.120.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 20:44:13.227745 2026] [security2:error] [pid 30332:tid 30332] [client 194.32.120.246:36349] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "87"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||linuxforpoets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "linuxforpoets.com"] [uri "/images/stories/themes.php"] [unique_id "agEmXUTl2iUszHemx5xG3AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-10 20:31:10
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
Octopuce
2026-05-10 17:28:16
(1 month ago)
Aggressive web search of vulnerable pages: /update/ /themes/zMousse/otuz1.php /wp-content/edit-wolf. ...
show more
Aggressive web search of vulnerable pages: /update/ /themes/zMousse/otuz1.php /wp-content/edit-wolf.php /wp-content/plugins/ubh/up.php /wp-admi ...
show less
Web App Attack
๐ต๐ญ
thezelijah
2026-05-09 14:43:00
(1 month ago)
Probing and recon. PHP and Config Hunting.
Port Scan
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
Gwyneth Llewelyn
2026-03-11 05:35:13
(3 months ago)
194.32.120.246 - - [11/Mar/2026:05:35:11 +0000] "GET /cgi-bin/index.php HTTP/1.1" 404 1117 "-" "Mozi ...
show more
194.32.120.246 - - [11/Mar/2026:05:35:11 +0000] "GET /cgi-bin/index.php HTTP/1.1" 404 1117 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36"
show less
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-02-23 12:29:41
(4 months ago)
194.32.120.246 - - [23/Feb/2026:14:29:40 +0200] "GET //wp-content/plugins/hello-plus/classes/ehp-soc ...
show more
194.32.120.246 - - [23/Feb/2026:14:29:40 +0200] "GET //wp-content/plugins/hello-plus/classes/ehp-social-elf.php HTTP/1.1" 404 278 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-02-23 10:15:45
(4 months ago)
194.32.120.246 - - [23/Feb/2026:12:15:44 +0200] "GET //wp-content/themes/Divi/404.php HTTP/1.1" 404 ...
show more
194.32.120.246 - - [23/Feb/2026:12:15:44 +0200] "GET //wp-content/themes/Divi/404.php HTTP/1.1" 404 288 "-" "Go-http-client/1.1"
194.32.120.246 - - [23/Feb/2026:12:15:45 +0200] "GET //wp-content/plugins/ubh/ubh.php HTTP/1.1" 404 288 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-02-23 09:05:29
(4 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-02-20 04:12:48
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:23:46
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 194.32.120.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 194.32.120.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:23:40.350542 2026] [security2:error] [pid 4233:tid 4233] [client 194.32.120.246:47339] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||powderriverinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "powderriverinc.com"] [uri "/back/mysql.sql"] [unique_id "aYqWrDL-RUcdkVteoESmYgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-01-25 20:03:55
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
Anonymous
2025-12-15 08:02:27
(6 months ago)
Blocked: Reason='Auto-block via DW'; Requests=0
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-06 17:42:57
(6 months ago)
(mod_security) mod_security (id:240000) triggered by 194.32.120.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 194.32.120.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 12:40:31.931834 2025] [security2:error] [pid 31461:tid 31461] [client 194.32.120.246:36499] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||mibfans.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "mibfans.com"] [uri "/images/stories/themes.php"] [unique_id "aTRqj4QnG4KjbHv2WNcC4gAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-12-06 17:30:56
(6 months ago)
Multiple WAF Violations
Web App Attack