๐ฉ๐ช
abdubhai
2026-05-06 06:23:27
(3 months ago)
45.67.99.32 - - [06/May/2026:11:
...
Brute-Force
๐ง๐ช
cmbplf
2026-05-06 05:37:25
(3 months ago)
1.221 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-06 05:30:37
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.67.99.32 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.67.99.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 01:30:34.826699 2026] [security2:error] [pid 24511:tid 24511] [client 45.67.99.32:49777] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.innovacionesnimba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.innovacionesnimba.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "afrR-r95cVx2Jk_ivWiS4wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-06 05:17:46
(3 months ago)
SQL Injection Attack Detected via libinjection. detected SQLi using libinjection with fingerprint 'n ...
show more
SQL Injection Attack Detected via libinjection. detected SQLi using libinjection with fingerprint 'n&1' (942100-196)
show less
SQL Injection
๐บ๐ธ
WeekendWeb
2026-05-06 04:34:38
(3 months ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-04 16:39:17
(3 months ago)
(mod_security) mod_security (id:234930) triggered by 45.67.99.32 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:234930) triggered by 45.67.99.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 12:39:09.987545 2026] [security2:error] [pid 16854:tid 16854] [client 45.67.99.32:57681] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||assec.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "assec.org"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "afjLrZiN0N9j4TOtqhbT_QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-04 13:01:41
(3 months ago)
(mod_security) mod_security (id:234930) triggered by 45.67.99.32 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:234930) triggered by 45.67.99.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 09:01:35.994188 2026] [security2:error] [pid 21223:tid 21223] [client 45.67.99.32:38617] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||avalonestates.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "avalonestates.org"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "afiYr-eByC70wnB_BYyINAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-05-04 12:45:06
(3 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ช๐ธ
masterguru
2026-05-04 09:49:27
(3 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-05-04 09:30:32
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฑ๐น
NotACaptcha
2026-05-04 07:26:50
(3 months ago)
webserver:80 [04/May/2026] "GET /gel4y.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 ...
show more
webserver:80 [04/May/2026] "GET /gel4y.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /login.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /xleet.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /about.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /style2.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /style.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /config.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /themes.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /file2.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /simple.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /chosen.php HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
webserver:80 [04/May/2026] "GET /inpu...
show less
Hacking
SQL Injection
Web App Attack
๐ซ๐ท
Octopuce
2026-05-03 19:23:02
(3 months ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/dzs-zoomsounds/1877.php /wp-content/p ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/dzs-zoomsounds/1877.php /wp-content/plugins/core-plugin/include.php /wp-content/ ...
show less
Web App Attack
๐ฆ๐บ
QT
2026-03-17 01:31:10
(5 months ago)
Website hack attempted at 2026-03-17 11:31:00 +1000
Web App Attack
๐ซ๐ท
dynamix
2026-03-16 20:31:18
(5 months ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-03-16 08:45:50
(5 months ago)
Web attack/malicious scanning detected
Web App Attack