๐ซ๐ท
Octopuce
2026-06-10 11:50:16
(2 months ago)
Aggressive web search of vulnerable pages: /wp-login.php?action=register /bless.php /O-Simple.php /l ...
show more
Aggressive web search of vulnerable pages: /wp-login.php?action=register /bless.php /O-Simple.php /lock360.php /zwso.php /chosen.php /about.php ...
show less
Web App Attack
๐ท๐บ
sms.ru
2026-06-07 14:11:08
(2 months ago)
/wp-admin/images/admin.php
Web App Attack
๐ฉ๐ช
zumbo.net
2026-06-07 06:01:58
(2 months ago)
[Sun Jun 07 09:00:21.862898 2026] [proxy_fcgi:error] [pid 87230:tid 87237] [client 45.154.138.16:0] ...
show more
[Sun Jun 07 09:00:21.862898 2026] [proxy_fcgi:error] [pid 87230:tid 87237] [client 45.154.138.16:0] AH01071: Got error 'Primary script unknown'
[Sun Jun 07 09:01:19.288478 2026] [proxy_fcgi:error] [pid 87229:tid 87281] [client 45.154.138.16:0] AH01071: Got error 'Primary script unknown'
[Sun Jun 07 09:01:26.519608 2026] [proxy_fcgi:error] [pid 87230:tid 87257] [client 45.154.138.16:0] AH01071: Got error 'Primary script unknown'
[Sun Jun 07 09:01:40.355608 2026] [proxy_fcgi:error] [pid 87230:tid 87257] [client 45.154.138.16:0] AH01071: Got error 'Primary script unknown'
[Sun Jun 07 09:01:56.920974 2026] [proxy_fcgi:error] [pid 87229:tid 87280] [client 45.154.138.16:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-06-07 04:47:21
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-06-07 00:28:52
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-06-05 05:06:42
(2 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-06-05 03:08:59
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐บ
oncord
2026-06-03 17:40:04
(2 months ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2026-05-15 04:53:17
(3 months ago)
Form spam
Web Spam
๐บ๐ฆ
URAN Publishing Service
2026-04-29 22:46:46
(3 months ago)
45.154.138.16 - - [30/Apr/2026:01:46:44 +0300] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1 ...
show more
45.154.138.16 - - [30/Apr/2026:01:46:44 +0300] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 404 708 "-" "Go-http-client/1.1"
45.154.138.16 - - [30/Apr/2026:01:46:45 +0300] "GET /wp-content/plugins/aatdgetgdg/main.php HTTP/1.1" 404 708 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 00:47:31
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.154.138.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.154.138.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 20:47:27.023136 2026] [security2:error] [pid 14691:tid 14691] [client 45.154.138.16:42213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.doreenkimura.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.doreenkimura.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aeQmH_-S4Nampmp9QWicSAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 00:26:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.154.138.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.154.138.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 20:26:06.796093 2026] [security2:error] [pid 329303:tid 329303] [client 45.154.138.16:45853] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chezlubacov.xyz|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chezlubacov.xyz"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aeQhHtlZZA-0G5nS6Sz-fQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 00:05:32
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.154.138.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.154.138.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 20:05:26.326166 2026] [security2:error] [pid 3786232:tid 3786232] [client 45.154.138.16:52881] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||noriega.us|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "noriega.us"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aeQcRsED4sA40tm9T44uugAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xserverx.ru
2026-04-17 04:38:09
(4 months ago)
Honeypot triggered:
IP: 45.154.138.16
Request to: https://xserverx.ru/vendor/phpunit/phpunit/phpunit ...
show more
Honeypot triggered:
IP: 45.154.138.16
Request to: https://xserverx.ru/vendor/phpunit/phpunit/phpunit.xsd
Method: GET
Host: xserverx.ru
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
Referer: Direct
Country: FR
ASN: Unknown
Triggered rules: /phpunit\.xsd, /vendor/, (X-Requested-With:\s*XMLHttpRequest)
Timestamp: 2026-04-17T04:38:09.680Z
show less
Hacking
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-04-17 01:03:20
(4 months ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot