๐จ๐ฆ
polycoda
2026-07-30 18:16:20
(17 hours ago)
๐ Probes for tons of inexistent files and/or PHP scripts
Hacking
Web App Attack
๐จ๐ฟ
ptlab
2026-07-30 14:30:02
(21 hours ago)
Detected forbidden path/plugin attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 13:14:34
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 23.154.136.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 23.154.136.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 09:14:26.074969 2026] [security2:error] [pid 2770923:tid 2770923] [client 23.154.136.143:17882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||web154.dnchosting.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "web154.dnchosting.com"] [uri "/admin/data/system/cluster.dat"] [unique_id "amtOMiL21mTyB_2tK54IcgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ป๐ณ
trung.fun
2026-07-30 13:08:52
(22 hours ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
๐ฎ๐ฉ
bps-statistics
2026-07-30 13:06:15
(22 hours ago)
Web Application Attacks
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-07-30 13:03:56
(22 hours ago)
[30/Jul/2026:14:03:59.277101 +0100] amtLv2Oh_G5AHVty0YIbRwAAAA0 23.154.136.143 39630 188.246.206.60 ...
show more
[30/Jul/2026:14:03:59.277101 +0100] amtLv2Oh_G5AHVty0YIbRwAAAA0 23.154.136.143 39630 188.246.206.60 7081
[30/Jul/2026:14:03:59.388430 +0100] amtLv2Oh_G5AHVty0YIbSAAAAAM 23.154.136.143 39632 188.246.206.60 7081
...
show less
Brute-Force
๐ฉ๐ช
Admins@FBN
2026-07-30 13:03:15
(22 hours ago)
FW-PortScan: Traffic Blocked srcport=27506 dstport=443
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-30 12:56:27
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 23.154.136.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 23.154.136.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 08:56:22.542607 2026] [security2:error] [pid 1754829:tid 1754829] [client 23.154.136.143:51292] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||learningbyshipping.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "learningbyshipping.com"] [uri "/admin/data/system/cluster.dat"] [unique_id "amtJ9peIWwZ5K393euUvcAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-07-30 12:51:03
(22 hours ago)
Port scanning / recon | Evidence: date=2026-07-30 time=14:49:21 devname="[redacted]" devid="[redacte ...
show more
Port scanning / recon | Evidence: date=2026-07-30 time=14:49:21 devname="[redacted]" devid="[redacted]" eventtime=1785415760756773429 tz=\"+0200\" logid=\"0000000013\" type=\"traffic\" subtype=\"forward\" level=\"notice\" vd="[redacted]" srcip=23.154.136.143 srcport=27380 srcintf="[redacted]" srcintfrole=\"wan\" dstip=[redacted] dstport=443 dstintf="[redacted]" dstintfrole=\"lan\" srccountry=\"United States\" dstcountry=\"Spain\" | ASN: AS-GLOBALTELEHOST | Country: US
show less
Port Scan
Web App Attack
๐บ๐ธ
SiliSoftware
2026-07-30 12:39:36
(22 hours ago)
/admin/data/system/cluster.dat
Web App Attack
๐ฆ๐บ
aranguren.org
2026-07-30 12:32:48
(23 hours ago)
23.154.136.143 - - [30/Jul/2026:22:17:36 +1000] "GET /admin/data/system/cluster.dat HTTP/1.1" 404 11 ...
show more
23.154.136.143 - - [30/Jul/2026:22:17:36 +1000] "GET /admin/data/system/cluster.dat HTTP/1.1" 404 1178 "https://zm.aranguren.org/admin/data/system/cluster.dat" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
23.154.136.143 - - [30/Jul/2026:22:17:38 +1000] "GET /htdocs/admin/data/system/cluster.dat HTTP/1.1" 404 1192 "https://zm.aranguren.org/htdocs/admin/data/system/cluster.dat" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
23.154.136.143 - - [30/Jul/2026:22:31:43 +1000] "GET /admin/data/system/cluster.dat HTTP/1.1" 404 1180 "https://ns2.aranguren.org/admin/data/system/cluster.dat" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
23.154.136.143 - - [30/Jul/2026:22:31:45 +1000] "GET /htdocs/admin/data/system/cluster.dat HTTP/1.1" 404 1194 "https://ns2.aranguren.org/htdocs/admin/data/system/cluster.dat" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
...
show less
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-07-30 12:22:00
(23 hours ago)
IPBlock protected site ID [955-wdo][s=11].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐น
mediarama.com
2026-07-30 12:20:29
(23 hours ago)
Banned by Fail2Ban
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-30 12:20:21
(23 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 23.154.136.143 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 23.154.136.143 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 12:19:07
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 23.154.136.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 23.154.136.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 08:19:00.694218 2026] [security2:error] [pid 3244435:tid 3244435] [client 23.154.136.143:43528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||web214.dnchosting.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "web214.dnchosting.com"] [uri "/admin/data/system/cluster.dat"] [unique_id "amtBNHU3MZBJaAyiyDu8wQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack