๐บ๐ธ
TPI-Abuse
2026-08-01 07:22:08
(4 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 03:22:02.394801 2026] [security2:error] [pid 12236:tid 12236] [client 2a04:c300:400::58:46336] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.ehrlichfamily.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.ehrlichfamily.com"] [uri "/"] [unique_id "am2emkkIRPOUFj5Fm1PFPQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-08-01 06:00:24
(5 hours ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 22295 (Advin Services LLC)
Protocol: HTTP ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 22295 (Advin Services LLC)
Protocol: HTTP/1.1 (POST method)
Endpoint: /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
Timestamp: 2026-08-01T04:05:27Z
User-Agent: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
show less
Bad Web Bot
๐ฌ๐ง
openstrike.co.uk
2026-08-01 05:14:24
(6 hours ago)
2 attacks on shell probes, PHP URLs:
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
POST /vendor/ ...
show more
2 attacks on shell probes, PHP URLs:
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 23:52:49
(11 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:52:46.326880 2026] [security2:error] [pid 3709013:tid 3709013] [client 2a04:c300:400::58:12782] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.styxwamworld.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.styxwamworld.com"] [uri "/"] [unique_id "am01Tu3JuGkvOloMPgRK6QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 22:52:57
(12 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:52:49.744547 2026] [security2:error] [pid 366375:tid 366375] [client 2a04:c300:400::58:54310] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.toybud.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.toybud.com"] [uri "/"] [unique_id "am0nQaXIIGHfQYO2B6CNMAAAAGw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 22:25:40
(13 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:25:36.860660 2026] [security2:error] [pid 1329317:tid 1329317] [client 2a04:c300:400::58:42184] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||autodiscover.ecomim.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "autodiscover.ecomim.com"] [uri "/"] [unique_id "am0g4IG5DqM6eMjVteFoCgAAAHA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 21:57:44
(13 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:57:36.040446 2026] [security2:error] [pid 1196006:tid 1196006] [client 2a04:c300:400::58:54474] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.tausiet.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.tausiet.com"] [uri "/"] [unique_id "am0aUInCBkw25bVTJ-wHqwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 21:38:07
(14 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:38:01.438922 2026] [security2:error] [pid 3277249:tid 3277249] [client 2a04:c300:400::58:50066] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.photoboothtogo.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.photoboothtogo.com"] [uri "/"] [unique_id "am0VuXVFtvXr9dvRZX_E0AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
NotACaptcha
2026-07-31 21:30:02
(14 hours ago)
webserver:443 [01/Aug/2026] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 946 "-" "Mozill ...
show more
webserver:443 [01/Aug/2026] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 946 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
webserver:443 [01/Aug/2026] "GET / HTTP/1.1" 302 427 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
webserver:443 [01/Aug/2026] "GET / HTTP/1.1" 302 427 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
webserver:443 [01/Aug/2026] "GET / HTTP/1.1" 302 5747 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
webserver:80 [01/Aug/2026] "GET / HTTP/1.1" 302 395 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
maxpower
2026-07-31 21:12:19
(14 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2a04:c300:400::58 (US/United States/-): ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2a04:c300:400::58 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a04:c300:400::58 - - [31/Jul/2026:23:12:17 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot" "-" host=avconsulenze.eu
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-31 20:27:03
(15 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 16:26:57.039149 2026] [security2:error] [pid 3769092:tid 3769198] [client 2a04:c300:400::58:59450] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||newsrank.hdtv55.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "newsrank.hdtv55.com"] [uri "/"] [unique_id "am0FERplrnGWcSPKbWe7WAAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
seal
2026-07-31 20:16:26
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-2021-41773
SSH
Brute-Force
๐ณ๐ฑ
BlueWire Hosting
2026-07-31 20:01:05
(15 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 18:12:49
(17 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 14:12:41.271640 2026] [security2:error] [pid 32243:tid 32243] [client 2a04:c300:400::58:13078] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "38"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||ipv6.nautanet.info|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "ipv6.nautanet.info"] [uri "/"] [unique_id "amzlmagVKOOhxSqEHARPYwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 16:27:37
(19 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:400::58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 12:27:31.378356 2026] [security2:error] [pid 3330083:tid 3330083] [client 2a04:c300:400::58:15700] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.eastbrooktech.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.eastbrooktech.com"] [uri "/"] [unique_id "amzM81dAiQXlSIWyVSU2EAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack