๐ฉ๐ช
bluematrix
2026-08-23 21:10:05
(16 minutes ago)
LePresidente/http-generic-403-bf - Ip 31.59.160.30 performed 'LePresidente/http-generic-403-bf' (6 e ...
show more
LePresidente/http-generic-403-bf - Ip 31.59.160.30 performed 'LePresidente/http-generic-403-bf' (6 events over 4.4932418s) at 2026-08-23 21:10:09.745669472 +0000 UTC
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ญ๐ท
bubausluge
2026-08-23 20:44:55
(41 minutes ago)
Blocked by https://aegis.hr โ WAF: SQL Injection Blind - (MITRE T1190), 8 attempts, Period: 2026-08- ...
show more
Blocked by https://aegis.hr โ WAF: SQL Injection Blind - (MITRE T1190), 8 attempts, Period: 2026-08-23 20:20:45 to 2026-08-23 20:20:46
show less
Web App Attack
Hacking
๐ซ๐ท
Zundapper
2026-08-23 20:06:43
(1 hour ago)
31.59.160.30 - - [23/Aug/2026:22:06:41 +0200] "GET /wp-admin/admin-ajax.php?action=acymailing_frontr ...
show more
31.59.160.30 - - [23/Aug/2026:22:06:41 +0200] "GET /wp-admin/admin-ajax.php?action=acymailing_frontrouter&columns=id%2Cname&ctrl=frontentityselect&entity=list&join=none&join_table=9753197531+AS+nx_gate&noheader=1&offset=0&perCalls=1&task=loadEntityFront HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
31.59.160.30 - - [23/Aug/2026:22:06:41 +0200] "GET /wp-admin/admin-ajax.php?action=acymailing_frontrouter&columns=id%2Cname&ctrl=frontentityselect&entity=user&join=none&join_table=9753197531+AS+nx_gate&noheader=1&offset=0&perCalls=1&task=loadEntityFront HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
31.59.160.30 - - [23/Aug/2026:22:06:41 +0200] "GET /wp-admin/admin-ajax.php?action=acymailing_frontrouter&columns=id%2Cname&ctrl=frontentityselect&entity=user&join=none&join_table=9753197531+AS+nx_gate&noheader=1&offset=0&
...
show less
Web App Attack
Port Scan
Anonymous
2026-08-23 16:50:05
(4 hours ago)
Automatic report - Vulnerability scan
$ 403 /signin
Web App Attack
Anonymous
2026-08-23 15:59:02
(5 hours ago)
[Sun Aug 23 17:58:59.373872 2026] [access_compat:error] [pid 1231437:tid 132068931512000] [client 31 ...
show more
[Sun Aug 23 17:58:59.373872 2026] [access_compat:error] [pid 1231437:tid 132068931512000] [client 31.59.160.30:36204] AH01797: client denied by server configuration: /var/www/html/
[Sun Aug 23 17:58:59.554574 2026] [access_compat:error] [pid 1231437:tid 132068700845760] [client 31.59.160.30:36204] AH01797: client denied by server configuration: /var/www/html/index.php
[Sun Aug 23 17:58:59.966186 2026] [access_compat:error] [pid 1231437:tid 132068835063488] [client 31.59.160.30:36204] AH01797: client denied by server configuration: /var/www/html/index.php
[Sun Aug 23 17:58:59.992194 2026] [access_compat:error] [pid 1231437:tid 132068012971712] [client 31.59.160.30:36204] AH01797: client denied by server configuration: /var/www/html/
[Sun Aug 23 17:59:00.029036 2026] [access_compat:error] [pid 1231437:tid 132068801492672] [client 31.59.160.30:36204] AH01797: client denied by server configuration: /var/www/html/
[Sun Aug 23 17:59:01.230402 2026] [access_compat:error] [pid 1231437:tid 1320
...
show less
Brute-Force
Web App Attack
Anonymous
2026-08-23 15:10:05
(6 hours ago)
Automatic report - Vulnerability scan
$ 403 /signup
Web App Attack
๐ณ๐ฑ
mieg
2026-08-23 11:22:41
(10 hours ago)
Web vulnerability probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 08:25:00
(13 hours ago)
(mod_security) mod_security (id:220150) triggered by 31.59.160.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:220150) triggered by 31.59.160.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 04:24:54.795686 2026] [security2:error] [pid 10684:tid 10684] [client 31.59.160.30:22138] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:columns. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||words.gmacguffin.com|F|2"] [data "idfrom#__acym_userasuserunionselectversion()#"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "words.gmacguffin.com"] [uri "/index.php"] [unique_id "aoquVnFqPsXEFm03Nl7vagAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRNP
2026-08-23 08:24:28
(13 hours ago)
_:443 31.59.160.30 - - [23/Aug/2026:08:24:24 +0000] "POST /index.php?rest_route=/batch/v1 HTTP/1.1" ...
show more
_:443 31.59.160.30 - - [23/Aug/2026:08:24:24 +0000] "POST /index.php?rest_route=/batch/v1 HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
_:443 31.59.160.30 - - [23/Aug/2026:08:24:24 +0000] "POST /index.php?rest_route=%2Fbatch%2Fv1 HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
_:443 31.59.160.30 - - [23/Aug/2026:08:24:25 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
_:443 31.59.160.30 - - [23/Aug/2026:08:24:25 +0000] "POST /wp-json/Batch/v1 HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
_:443 31.59.160.30 - - [23/Aug/2026:08:24:25 +0000] "POST //wp-json/batch/v1 HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Som1ght3n
2026-08-23 08:12:39
(13 hours ago)
IP scanned for OVH hostnames, attempting to access '/batch/v1' via HTTP POST, indicative of a web ap ...
show more
IP scanned for OVH hostnames, attempting to access '/batch/v1' via HTTP POST, indicative of a web application attack.
show less
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-08-23 08:10:25
(13 hours ago)
Threat Intelligence via ARMTI, Web Attack: POST /index.php?rest_route=%2Fbatch%2Fv1
Web App Attack
๐ฉ๐ช
pscriptos
2026-08-23 07:56:25
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐จ๐ฟ
kronos
2026-08-23 07:52:41
(13 hours ago)
IDS: ATTACK [PTsecurity] React Server Components RCE (CVE-2025-55182) | SID:10016007 | session_sigs: ...
show more
IDS: ATTACK [PTsecurity] React Server Components RCE (CVE-2025-55182) | SID:10016007 | session_sigs:3
show less
Hacking
Web App Attack
๐ณ๐ฑ
lid3rc
2026-08-23 07:50:38
(13 hours ago)
According to the AbuseIPDB risk analysis, the IP address is too high risk.
Web App Attack
Anonymous
2026-08-23 07:48:02
(13 hours ago)
WEB attack
Brute-Force