๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-07-23 07:20:36
(1 month ago)
JKweb Security: Severe and dangerous web attack detected. Attacker permanently banned by Fail2Ban.
Port Scan
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-06-26 15:20:11
(2 months ago)
๐ฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
Anonymous
2026-04-04 23:57:16
(4 months ago)
HTTPS vulnerability scan attempt detected. Port 443.
Hacking
SQL Injection
Web App Attack
๐ซ๐ท
conseilgouz
2026-04-04 23:57:09
(4 months ago)
upe-12 : Block return, carriage return, ... characters=>/index.php?option=com_content'[0]&v ...
show more
upe-12 : Block return, carriage return, ... characters=>/index.php?option=com_content'[0]&view=article&id=118&catid=13(')
show less
Hacking
๐จ๐ฆ
polycoda
2026-04-04 20:28:48
(4 months ago)
AutoBlock: ๐ SQL Injection Attempt (Non Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-04 16:42:20
(4 months ago)
IM360 WAF: Infectors: OS File Access Attempt MV:/etc/passwd
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-04 16:42:18
(4 months ago)
IM360 WAF: Generic XSS exploitation attempt MV:"><script >alert(String.fromCharCode(88,83,83))</scri ...
show more
IM360 WAF: Generic XSS exploitation attempt MV:"><script >alert(String.fromCharCode(88,83,83))</script>
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 17:14:40
(4 months ago)
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 13:14:33.620622 2026] [security2:error] [pid 20166:tid 20166] [client 50.114.10.199:59078] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||fiyaplatform.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /fiyacore/music.php?genre=18&sort=\\x22><script>alert(string.fromcharcode(88,83,83))</script>&page=2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "fiyaplatform.com"] [uri "/fiyacore/music.php"] [unique_id "ac6j-SHTYNsJSK3NHyPqnAAAABE"], referer: https://fiyaplatform.com/fiyacore/music.php?genre=18&sort="><script >alert(String.fromCharCode(88,83,83))</script>&page=2
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
kk_it_man
2026-04-02 12:03:01
(4 months ago)
ET WEB_SERVER /etc/passwd Detected in URI
ET WEB_SERVER Script tag in URI Possible Cross Site Scri ...
show more
ET WEB_SERVER /etc/passwd Detected in URI
ET WEB_SERVER Script tag in URI Possible Cross Site Scripting Attempt
GPL WEB_SERVER 403 Forbidden
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-02 09:31:58
(4 months ago)
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 05:31:54.604780 2026] [security2:error] [pid 3022:tid 3081] [client 50.114.10.199:64803] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.ajbruner.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /ct/shop/index.php?main_page=\\x22><script>alert(string.fromcharcode(88,83,83))</script>&cpath=15_5_11&products_id=83"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.ajbruner.com"] [uri "/ct/shop/index.php"] [unique_id "ac43ijN1_fqXe9LddWQaPAAAANY"], referer: https://www.ajbruner.com/ct/shop/index.php?main_page="><script >alert(String.fromCharCode(88,83,83))</script>&cPath=15_5_11&products_id=83
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 05:00:10
(4 months ago)
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 01:00:02.519752 2026] [security2:error] [pid 25475:tid 25475] [client 50.114.10.199:49607] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.sports.grimone.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /gallery.php?bld=\\x22><script>alert(string.fromcharcode(88,83,83))</script>&sport=basketball&year=1974&type=cards"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.sports.grimone.com"] [uri "/gallery.php"] [unique_id "ac330hy9POHF5gdQ10OKjAAAAA4"], referer: https://www.sports.grimone.com/gallery.php?bld="><script >alert(String.fromCharCode(88,83,83))</script>&sport=basketball&year=1974&type=cards
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 02:47:07
(4 months ago)
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 22:47:00.483529 2026] [security2:error] [pid 13523:tid 13523] [client 50.114.10.199:57612] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "3"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||neff.family.name|F|2"] [data "Matched Data: <script found within REQUEST_URI: /unwiki/doku.php?id=\\x22><script>alert(string.fromcharcode(88,83,83))</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "neff.family.name"] [uri "/unwiki/doku.php"] [unique_id "ac3YpLWiVeQ75sa3QousZQAAAAk"], referer: https://neff.family.name/unwiki/doku.php?id="><script >alert(String.fromCharCode(88,83,83))</script>
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 02:02:56
(4 months ago)
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 22:02:51.588880 2026] [security2:error] [pid 29802:tid 29802] [client 50.114.10.199:62854] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.cs-mall.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /category.php?cat=\\x22><script>alert(string.fromcharcode(88,83,83))</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.cs-mall.com"] [uri "/category.php"] [unique_id "ac3OS0dJT9Njk6MJX7SsiQAAAAc"], referer: http://www.cs-mall.com/category.php?cat="><script >alert(String.fromCharCode(88,83,83))</script>
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-04-01 19:02:12
(4 months ago)
Malformed or malicious web request
50.114.10.199 - - [01/Apr/2026:21:02:08 +0200] "GET /index.php?ti ...
show more
Malformed or malicious web request
50.114.10.199 - - [01/Apr/2026:21:02:08 +0200] "GET /index.php?title=Butcher's_Imp'[0]&redirect=no HTTP/1.1" 400 9091 "https://wiki.<REDACTED>/index.php?title=Butcher's_Imp'[0]&redirect=no" "Mozilla/5.0 (Windows NT 10.0; WOW64; Rv:50.0) Gecko/20100101 Firefox/50.0"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 17:02:55
(4 months ago)
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 50.114.10.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 13:02:48.995936 2026] [security2:error] [pid 9189:tid 9189] [client 50.114.10.199:55785] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||navigateworklife.org|F|2"] [data "Matched Data: <script found within REQUEST_URI: /switch-quiz01.php?source=\\x22><script>alert(string.fromcharcode(88,83,83))</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "navigateworklife.org"] [uri "/switch-quiz01.php"] [unique_id "ac1PuF-Fb3-3HMvNteelsQAAAA8"], referer: http://navigateworklife.org/switch-quiz01.php?source="><script >alert(String.fromCharCode(88,83,83))</script>
show less
Brute-Force
Bad Web Bot
Web App Attack