Anonymous
2026-04-08 07:59:20
(6 months ago)
Credential Stuffing attacks against Microsoft 365
Brute-Force
๐บ๐ธ
mnsf
2026-02-21 16:05:33
(7 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-02-21 14:47:28
(7 months ago)
195.210.107.18 - - [21/Feb/2026:16:47:27 +0200] "GET //wp-content/plugins/wpforms/class-wpforms-upda ...
show more
195.210.107.18 - - [21/Feb/2026:16:47:27 +0200] "GET //wp-content/plugins/wpforms/class-wpforms-update.php HTTP/1.1" 404 276 "-" "Go-http-client/1.1"
195.210.107.18 - - [21/Feb/2026:16:47:27 +0200] "GET //wp-content/plugins/phpadmin/autoload_classmap.php HTTP/1.1" 404 276 "-" "Go-http-client/1.1"
...
show less
Web App Attack
Anonymous
2026-02-19 19:05:18
(7 months ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (15/60 min)'; Requests=15
Port Scan
๐ซ๐ท
dynamix
2026-02-19 18:59:43
(7 months ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
Origon
2026-02-19 14:17:19
(7 months ago)
http-admin-interface-probing - IP: 195.210.107.18 - time="2026-02-19T15:17:19+01:00" level=info msg ...
show more
http-admin-interface-probing - IP: 195.210.107.18 - time="2026-02-19T15:17:19+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-admin-interface-probing by ip 195.210.107.18 (US/137409) : 4h ban on Ip 195.210.107.18" module=db
show less
Web App Attack
Anonymous
2026-02-19 12:00:02
(7 months ago)
suspicious request in access.log
Web App Attack
๐ง๐ช
cmbplf
2026-02-18 20:33:03
(7 months ago)
203 requests with url.path */.well-known/acme-challenge/*.php
Brute-Force
Bad Web Bot
๐ฌ๐ง
consul.to
2026-02-18 16:19:44
(7 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 14:10:49
(7 months ago)
(mod_security) mod_security (id:240000) triggered by 195.210.107.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 195.210.107.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 09:10:44.573922 2026] [security2:error] [pid 31900:tid 31900] [client 195.210.107.18:23357] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||72blues.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "72blues.com"] [uri "/images/stories/themes.php"] [unique_id "aZXIZAMXwNt0weM84lPYuAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:21:09
(7 months ago)
(mod_security) mod_security (id:240000) triggered by 195.210.107.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 195.210.107.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:21:05.532555 2026] [security2:error] [pid 28101:tid 28127] [client 195.210.107.18:35713] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||particulierlb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "particulierlb.com"] [uri "/images/stories/themes.php"] [unique_id "aZWgoSukGBBJynT8tkRnvQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-03 02:52:04
(9 months ago)
Botnet activity detected: Wide horizontal scanner, Horizontal with multiple indicators, Horizontal s ...
show more
Botnet activity detected: Wide horizontal scanner, Horizontal with multiple indicators, Horizontal scan with SYN retry, Confirmed scanner identified, Multiple scan indicators, Slow horizontal with regular pattern, Mixed vertical+horizontal scanner, Coordinated non-service scan, Multiple non-service patterns, Confirmed scanner with multiple patterns (+2 more). Total 82 blocks.
show less
DDoS Attack
Port Scan
Hacking
๐บ๐ธ
RLDD
2025-11-21 06:54:35
(10 months ago)
WP probing -nov
Web App Attack
๐ณ๐ฑ
jjnxpct
2025-11-21 04:46:48
(10 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /contact/informatieformulier (Rule ID: 932235) - Remote Command Execution: Unix Command Injection (command without evasion)
show less
SQL Injection
Web App Attack
๐บ๐ธ
oncord
2025-11-20 12:40:47
(10 months ago)
Form spam
Web Spam