๐ซ๐ท
pm33
2026-03-20 12:32:45
(2 months ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐ซ๐ท
Octopuce
2026-03-06 22:11:00
(2 months ago)
Aggressive web search of vulnerable pages: //modules/scrollbottom/anamama-2.php //modules/mod_simple ...
show more
Aggressive web search of vulnerable pages: //modules/scrollbottom/anamama-2.php //modules/mod_simplefileuploadv1.3/elements/filemanager.php //4 ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 06:18:20
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 01:18:13.442622 2026] [security2:error] [pid 28883:tid 28883] [client 212.30.37.28:48607] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pellman-world.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pellman-world.com"] [uri "/back/www.sql"] [unique_id "aaUrpYNEVNROle9_R3WcEAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-02-23 23:18:00
(3 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2026-02-23 22:02:15
(3 months ago)
Multiple, malicious web requests detected
Port Scan
Hacking
๐ฏ๐ต
Valhalla
2026-02-17 19:09:03
(3 months ago)
/bak/Archive.zip
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-06 02:05:46
(3 months ago)
Attempted access to sensitive endpoint (/blog/) detected. Automated scan or unauthorized probing.
Web App Attack
๐ฏ๐ต
Valhalla
2026-02-04 14:12:52
(3 months ago)
/backup.gz
Hacking
Web App Attack
๐บ๐ธ
Penny Packer
2026-02-02 14:45:06
(4 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ต๐ฑ
IROK
2026-02-01 09:30:30
(4 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-31 20:02:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 31 15:02:05.812505 2026] [security2:error] [pid 30288:tid 30288] [client 212.30.37.28:44361] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feaverslane.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "aX5fvZdqGArBpLR9pbD_1wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-31 04:24:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 23:24:39.500354 2026] [security2:error] [pid 5166:tid 5166] [client 212.30.37.28:35801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "endemic.com"] [uri "/.env.production"] [unique_id "aX2EB47v0CbfrXu0_KINjAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-31 02:18:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 21:18:17.077176 2026] [security2:error] [pid 20004:tid 20004] [client 212.30.37.28:56221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vmbinc.com"] [uri "/sftp-config.json"] [unique_id "aX1maZAO7aV8ienVO7uCzgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-31 00:10:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 19:10:05.907803 2026] [security2:error] [pid 20531:tid 20531] [client 212.30.37.28:25325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hogprinter.com"] [uri "/.env"] [unique_id "aX1IXRKwrf39SsURqce5xAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-01-13 03:19:48
(4 months ago)
Apache 403 Forbidden Access. Evidence: [REDACTED_DOMAIN]:80 212.30.37.28 - - [13/Jan/2026:03:19:44 + ...
show more
Apache 403 Forbidden Access. Evidence: [REDACTED_DOMAIN]:80 212.30.37.28 - - [13/Jan/2026:03:19:44 +0000] GET /info.php HTTP/1.1 403 214 - Mozilla/5.0 (X11; Linux x86_64; rv:105.0) Gecko/20100101 Firefox/105.0
show less
Web App Attack