๐ณ๐ฑ
Alt255
2026-09-15 17:48:48
(4 days ago)
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 19 ...
show more
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 199.235.135.239 - - [11/Sep/2026:08:38:45 +0200] "GET /wp-content/plugins/buddypress/alfa.php HTTP/1.1" 404 696 "-" "Go-http-client/1.1"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 10:47:59
(5 days ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (14/60 min)'; Requests=14
Port Scan
๐ซ๐ท
Octopuce
2026-09-12 03:35:03
(1 week ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/neoncore-themes/O/SrHD3odefault.php / ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/neoncore-themes/O/SrHD3odefault.php /wp-content/plugins/bbpress/file5.php /wp-in ...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-11 03:50:52
(1 week ago)
[11/Sep/2026:06:50:51 +0300] -- 199.235.135.239 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-10 14:25:03
(1 week ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-10 12:06:07
(1 week ago)
Web probing (12 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by C ...
show more
Web probing (12 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
Anonymous
2026-09-10 10:27:56
(1 week ago)
IP matched detection query many 3xx errors.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-10 04:09:27
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 199.235.135.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 199.235.135.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 00:09:22.453623 2026] [security2:error] [pid 2412:tid 2412] [client 199.235.135.239:51305] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.airdriedrivingschool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.airdriedrivingschool.com"] [uri "/images/stories/themes.php"] [unique_id "aqItckTMN6AfeeYXiOEY1wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 03:24:20
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 199.235.135.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 199.235.135.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 23:24:03.877670 2026] [security2:error] [pid 8108:tid 8108] [client 199.235.135.239:23075] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.wryemusings.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.wryemusings.com"] [uri "/images/stories/themes.php"] [unique_id "aqIi0xX_OFPcDsFK34_9OQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-09 20:30:49
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-09 15:17:35
(1 week ago)
(upload_shell) srv104 PHP Shell Upload 199.235.135.239 (TH/Thailand/-): 1 in the last 3600 secs; Por ...
show more
(upload_shell) srv104 PHP Shell Upload 199.235.135.239 (TH/Thailand/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 11:45:27
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 199.235.135.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240000) triggered by 199.235.135.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:45:22.892951 2026] [security2:error] [pid 11708:tid 11708] [client 199.235.135.239:59205] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||notforhirellc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "notforhirellc.com"] [uri "/images/stories/themes.php"] [unique_id "aqFG0hJ-kVRRHddepNuUUQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
[email protected]
2026-08-28 11:09:57
(3 weeks ago)
PrestaShop Security Module: WordPress probe path detected
Web App Attack
๐จ๐ญ
backslash
2026-08-28 10:03:01
(3 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-08-28 08:31:32
(3 weeks ago)
[28/Aug/2026:11:31:32 +0300] -- 199.235.135.239 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack