๐ณ๐ฑ
mar kla
2026-08-01 22:14:00
(8 hours ago)
Searching for vulnerable scripts
Port Scan
Brute-Force
Exploited Host
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-01 06:53:58
(23 hours ago)
(mod_security) mod_security (id:211190) triggered by 204.194.54.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 204.194.54.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 02:53:53.393846 2026] [security2:error] [pid 1584211:tid 1584211] [client 204.194.54.240:47348] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||vccemail.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /images/?rllh=8707%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vccemail.net"] [uri "/images/"] [unique_id "am2YAZRBBZw4KAQUdIpc6AAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jcbriar
2026-07-31 14:43:41
(1 day ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐บ๐ธ
nyt
2026-07-31 13:38:32
(1 day ago)
SQLi (boolean), XSS, Path Traversal, Path Traversal
SQL Injection
Web App Attack
๐ฉ๐ช
raph
2026-07-31 06:15:45
(2 days ago)
[SQL INJECTION] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(%20AND%20|%2 ...
show more
[SQL INJECTION] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(%20AND%20|%20and%20|%20OR%20|%20or%20).* HTTP/1.1$
show less
SQL Injection
๐ซ๐ท
dynamix
2026-07-31 03:54:21
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 02:53:19
(2 days ago)
(mod_security) mod_security (id:211190) triggered by 204.194.54.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 204.194.54.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 22:53:12.645581 2026] [security2:error] [pid 2043006:tid 2043006] [client 204.194.54.240:43794] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||sawmat.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /images/?C=D%3BO=A&LIoU=7626%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sawmat.com"] [uri "/images/"] [unique_id "amwOGJ-vHDfrDC-slWyWSQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-30 19:46:05
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 204.194.54.240 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 204.194.54.240 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐ซ๐ท
COMAITE
2026-07-30 18:00:58
(2 days ago)
SQL injection attempt from 204.194.54.240.
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-30 13:25:02
(2 days ago)
[Thu Jul 30 23:25:01.124909 2026] [security2:error] [pid 529993] [client 204.194.54.240:40356] [clie ...
show more
[Thu Jul 30 23:25:01.124909 2026] [security2:error] [pid 529993] [client 204.194.54.240:40356] [client 204.194.54.240] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 75)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/tag/joomla/"] [unique_id "amtQrfLE6h9aMLac7kIq8gAAAAU"]
...
show less
Web App Attack
๐บ๐ธ
nyt
2026-07-30 09:16:01
(2 days ago)
SQLi (boolean), XSS, Path Traversal, Path Traversal
SQL Injection
Web App Attack
๐ซ๐ท
Sorgin Informatique
2026-07-30 06:09:23
(3 days ago)
nee-7 : Trying access unauthorized files/dir=>/index.php/sources-et-licences-des-images?aRfm=3560%20 ...
show more
nee-7 : Trying access unauthorized files/dir=>/index.php/sources-et-licences-des-images?aRfm=3560%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%...
show less
Hacking
Anonymous
2026-07-29 15:05:38
(3 days ago)
Blocked: Reason='Possible SQL injection activity (3/60 min)'; Requests=3
SQL Injection
๐ณ๐ฑ
javierin
2026-07-27 07:31:49
(5 days ago)
204.194.54.240 - javierin.com - - [27/Jul/2026:07:31:49 +0000] "GET /tag/imagenes-wordpress/?WPIr=78 ...
show more
204.194.54.240 - javierin.com - - [27/Jul/2026:07:31:49 +0000] "GET /tag/imagenes-wordpress/?WPIr=7899%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23 HTTP/1.1" 403 "https://javierin.com/tag/imagenes-wordpress/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" SQLI-BLOCKED
...
show less
SQL Injection
Web App Attack
๐บ๐ธ
nyt
2026-07-27 04:55:57
(6 days ago)
SQLi (boolean), XSS, Path Traversal, Path Traversal
SQL Injection
Web App Attack