🇩🇪
st-secure-team
2026-07-26 18:42:00
(2 days ago)
Фейк GoogleBot, Брутфорс, Поиск бекдоров, ищет уязвимости в Hongdian H8922, SQL инъекции, распределё ...
show more
Фейк GoogleBot, Брутфорс, Поиск бекдоров, ищет уязвимости в Hongdian H8922, SQL инъекции, распределённая бот атака, Ботнет, поиск файлов окружения, Хостинг C2 для WordPress бекдора.
show less
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
Hacking
SQL Injection
🇩🇪
bsoft.de
2026-07-26 13:17:39
(2 days ago)
31.58.23.47 - - [26/Jul/2026:15:17:38 +0200] "GET /robots.txt HTTP/1.1" 200 4210 "-" "Googlebot"
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-17 06:01:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 01:00:57.370533 2026] [security2:error] [pid 17282:tid 17282] [client 31.58.23.47:44711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.bak"] [unique_id "aWslmdEf9wGiZohZDHyy1gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 19:06:23
(6 months ago)
(mod_security) mod_security (id:211190) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:06:17.548656 2025] [security2:error] [pid 22840:tid 22948] [client 31.58.23.47:46847] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /install/lib/ajaxHandlers/ajaxServerSettingsChk.php?rootUname=%3b%63%61%74%20%2f%65%74%63%2f%70%61%73%73%77%64%20%23"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/install/lib/ajaxHandlers/ajaxServerSettingsChk.php"] [unique_id "aVLRKfUSdzJ-gbjPWKhQiwAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-13 10:23:02
(8 months ago)
(mod_security) mod_security (id:211190) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:22:51.196387 2025] [security2:error] [pid 31280:tid 31280] [client 31.58.23.47:59741] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?action=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/"] [unique_id "aRWxe1SnbhgA4IRsQrclKAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-29 18:24:05
(8 months ago)
(mod_security) mod_security (id:211190) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 14:23:56.934531 2025] [security2:error] [pid 26379:tid 26379] [client 31.58.23.47:44473] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.davispickering.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /card_scan.php?No=30&ReaderNo=%60cat%20/etc/passwd%20%3E%20kPWSYzOVFv.txt%60"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.davispickering.com"] [uri "/card_scan.php"] [unique_id "aQJbvCjYcDCq7jbj6DJqNAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
RoboSOC
2025-10-16 08:46:02
(9 months ago)
Hongdian H8922 Industrial Router Remote Command Execution Vulnerability, PTR: PTR record not found
Hacking
🇺🇸
TPI-Abuse
2025-07-27 00:22:31
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:22:11.076682 2025] [security2:error] [pid 172499:tid 172607] [client 31.58.23.47:48647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/.env.save"] [unique_id "aIVxM4En7YGnahfIo_jI3wAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-25 10:00:49
(1 year ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-29 17:15:20
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:218420) triggered by 31.58.23.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 13:15:14.548077 2025] [security2:error] [pid 3048191:tid 3048191] [client 31.58.23.47:33949] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||ftp.farmers123.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "ftp.farmers123.com"] [uri "/index.php"] [unique_id "aDiWIl6c2YXMCvng3Df6hwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-25 19:40:12
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack