๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-05-01 06:12:32
(1 month ago)
WP Login Scan Activities: "2026-05-01T13:12:32.289+07:00" "/wp-login.php" "194.70.234.38" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-05-01T13:12:32.289+07:00" "/wp-login.php" "194.70.234.38" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-04-28 20:01:12
(1 month ago)
WP Login Scan Activities: "2026-04-29T03:01:12.756+07:00" "/wp-login.php" "194.70.234.38" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-04-29T03:01:12.756+07:00" "/wp-login.php" "194.70.234.38" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 13:39:20
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 194.70.234.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 194.70.234.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 09:39:12.593378 2026] [security2:error] [pid 22723:tid 22723] [client 194.70.234.38:59475] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sdqdesigns.timelord2067.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sdqdesigns.timelord2067.com"] [uri "/s3cmd.ini"] [unique_id "afC4gK9xJ8VNASL6LOigvgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 20:01:04
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 194.70.234.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 194.70.234.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 16:00:56.064218 2026] [security2:error] [pid 13564:tid 13564] [client 194.70.234.38:55797] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chavarri.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chavarri.com"] [uri "/s3cmd.ini"] [unique_id "ae5u-MBFd9Stbwlvb2z8lAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-04-26 11:59:30
(1 month ago)
[SunApr2613:59:27.0231892026][security2:error][pid2044834:tid2044895][client194.70.234.38:0]ModSecur ...
show more
[SunApr2613:59:27.0231892026][security2:error][pid2044834:tid2044895][client194.70.234.38:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"serversvizzera.ch\"][uri\"/\"][unique_id\"ae3-H48f2udriwrxP6CuiAAAAFg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 04:00:29
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 194.70.234.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.70.234.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 00:00:25.661686 2026] [security2:error] [pid 3138506:tid 3138506] [client 194.70.234.38:34049] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||web.cruisingforsex.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "web.cruisingforsex.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aemZWRL2JEKDeQsltixHZQAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
SOC PR
2026-04-13 07:16:12
(2 months ago)
IPS: WordPress HTTP Brute Force Login Attempt.
Brute-Force
Anonymous
2026-02-18 05:45:50
(4 months ago)
GlobalProtect Password Spraying
Brute-Force
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-10 14:34:34
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-03-09 21:39:28
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 194.70.234.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.70.234.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 17:39:21.086751 2025] [security2:error] [pid 30019:tid 30019] [client 194.70.234.38:24427] [client 194.70.234.38] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "milajarecords.com"] [uri "/.env"] [unique_id "Z84KidFUkcq3ZrNff-Sy7QAAACU"], referer: https://tasamm.com/about/mmm171.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
sms.ru
2024-09-23 00:45:05
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
๐ช๐ธ
el-brujo
2024-06-09 21:23:00
(2 years ago)
DDoS Attack Layer 7 - REQUESTS / HTTP/2.0
DDoS Attack