Anonymous
2026-06-04 00:10:37
(1 day ago)
curl https://gsocket.io/y
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
Lunix
2026-06-03 15:28:55
(1 day ago)
Brute-Force
Web App Attack
๐ซ๐ฎ
tjs
2026-06-03 09:55:00
(1 day ago)
web attack, shell attempt
Hacking
Web App Attack
๐ฏ๐ต
VXG-NET
2026-06-03 08:47:52
(1 day ago)
port=80, indicator_type=code-execution
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-03 02:59:19
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.217.253.159 (vmi3318000.contaboserver.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 217.217.253.159 (vmi3318000.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 22:59:14.688091 2026] [security2:error] [pid 19243:tid 19243] [client 217.217.253.159:57405] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.famagustacyprus.eu|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.famagustacyprus.eu"] [uri "/wp-json/wp/v2/users"] [unique_id "ah-YgnucmhsAOSNqRSCZxQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 02:45:07
(1 day ago)
Command Injection Exploit Sensor - HTTP (Request) - Variant 2
Hacking
๐ฎ๐ฉ
zam
2026-06-02 20:55:47
(2 days ago)
217.217.253.159 - - [02/Jun/2026:20:55:44 +0000] "GET /24/local/moodle_webshell/webshell.php?action= ...
show more
217.217.253.159 - - [02/Jun/2026:20:55:44 +0000] "GET /24/local/moodle_webshell/webshell.php?action=exec\u0026cmd=id HTTP/1.1" 301 335
show less
Web App Attack
๐จ๐ฆ
1gz
2026-06-01 12:10:47
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-login.php
UA: Mozila/5.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
Lunix
2026-06-01 08:43:59
(3 days ago)
Brute-Force
Web App Attack
๐ฎ๐ฉ
soc-yk
2026-05-31 22:54:12
(4 days ago)
Type: web_scanning
Threat: unknown
Risk: 74
Events: 218
Evidence:
- Automated hostile web probing d ...
show more
Type: web_scanning
Threat: unknown
Risk: 74
Events: 218
Evidence:
- Automated hostile web probing detected
- Repeated web scanning activity observed
- Multi-event operational persistence identified
- Threat escalation behavior observed
show less
Web App Attack
๐ซ๐ท
tilellit.pro
2026-05-31 12:47:05
(4 days ago)
Fail2Ban banned 217.217.253.159 for security violations in jail wp-armour. Log: 2026/05/31 12:47:04 ...
show more
Fail2Ban banned 217.217.253.159 for security violations in jail wp-armour. Log: 2026/05/31 12:47:04 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 217.217.253.159 | Target: wplogin" , client: 217.217.253.159, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED]
...
show less
Web Spam
๐จ๐ฆ
1gz
2026-05-31 11:43:57
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-login.php
UA: Mozila/5.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
Lunix
2026-05-29 12:38:03
(6 days ago)
Brute-Force
Web App Attack
๐ฎ๐ฉ
soc-yk
2026-05-26 17:22:12
(1 week ago)
Type: credential_attack
Threat: credential_spraying_actor
Risk: 65
Events: 310
Evidence:
- Repeated ...
show more
Type: credential_attack
Threat: credential_spraying_actor
Risk: 65
Events: 310
Evidence:
- Repeated authentication attack activity detected
- Credential abuse behavior observed
- Multi-event operational persistence identified
show less
Brute-Force
SSH
๐ง๐ช
Saec
2026-05-25 15:00:07
(1 week ago)
Jarvis auto-ban: CF honeypot path /wp-login.php (1ร on saec.me)
Port Scan
Web App Attack