🇱🇻
garmtech.com
2026-08-07 22:21:56
(4 weeks ago)
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:0
Hacking
🇷🇺
sms.ru
2026-06-07 14:12:36
(2 months ago)
/wp-admin/css/colors/light/colors.min.php
Web App Attack
🇫🇷
Octopuce
2026-06-07 03:49:08
(3 months ago)
Aggressive web search of vulnerable pages: /lock.php /wp-admin/css/colors/blue/gold.php /wp-includes ...
show more
Aggressive web search of vulnerable pages: /lock.php /wp-admin/css/colors/blue/gold.php /wp-includes/atomlib.php /wp-includes/rest-api/index.ph ...
show less
Web App Attack
🇫🇮
inlink.ltd
2026-06-07 02:30:11
(3 months ago)
Known malicious PHP file or CMS probe
Web App Attack
🇫🇷
dynamix
2026-06-07 00:29:32
(3 months ago)
Multiple WAF Violations
Web App Attack
🇫🇷
SpaceHost-Server
2026-05-24 22:36:58
(3 months ago)
Brute-Force
Web App Attack
🇩🇪
macrob
2026-05-24 14:07:05
(3 months ago)
2026/05/24 14:07:03 [error] 3436711#3436711: *252898076 access forbidden by rule, client: 45.154.138 ...
show more
2026/05/24 14:07:03 [error] 3436711#3436711: *252898076 access forbidden by rule, client: 45.154.138.28, server: binixo.pl, request: "GET //wp-includes/ID3/license.txt HTTP/2.0", host: "binixo.pl"
2026/05/24 14:07:04 [error] 3436713#3436713: *252893516 access forbidden by rule, client: 45.154.138.28, server: binixo.pl, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "binixo.pl"
2026/05/24 14:07:04 [error] 3436710#3436710: *252895399 access forbidden by rule, client: 45.154.138.28, server: binixo.pl, request: "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0", host: "binixo.pl"
...
show less
Web App Attack
🇨🇦
Mediashaker
2026-05-06 00:21:29
(4 months ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 45.154.138.28 (FR/France ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 45.154.138.28 (FR/France/-)
show less
Port Scan
🇺🇸
TPI-Abuse
2026-04-19 09:11:13
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.154.138.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.154.138.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 05:11:10.363224 2026] [security2:error] [pid 1730965:tid 1730965] [client 45.154.138.28:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||antitribu.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "antitribu.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aeScLtF8HYwlEmrEnbLblAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-19 00:56:03
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.154.138.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.154.138.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 20:55:57.898581 2026] [security2:error] [pid 13826:tid 13826] [client 45.154.138.28:43447] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brucerohrphotography.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brucerohrphotography.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aeQoHUYqCb2txRFvobBMKwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-19 00:23:06
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.154.138.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.154.138.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 20:22:59.312375 2026] [security2:error] [pid 326520:tid 326520] [client 45.154.138.28:52157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hakanararat.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hakanararat.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aeQgY7WQIwL3HyjLkNwK6AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-19 00:06:25
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.154.138.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.154.138.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 20:06:19.864026 2026] [security2:error] [pid 3800416:tid 3800416] [client 45.154.138.28:49865] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||limegreenvinyl.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "limegreenvinyl.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aeQce1Ue5h7pgtTw3Y5-vgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-04-08 01:57:00
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇸🇪
SkyDancer
2026-03-23 10:46:42
(5 months ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
Anonymous
2026-03-21 20:57:59
(5 months ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force