๐ฉ๐ช
4server
2026-07-20 18:58:44
(4 hours ago)
[MonJul2020:58:39.8066472026][security2:error][pid2135218:tid2135233][client62.72.5.52:0]ModSecurity ...
show more
[MonJul2020:58:39.8066472026][security2:error][pid2135218:tid2135233][client62.72.5.52:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bhttpx\\\\\\\\b\|\\\\\\\\bnaabu\\\\\\\\b\|\\\\\\\\bffuf\\\\\\\\b\|\\\\\\\\bgobuster\\\\\\\\b\|\\\\\\\\bferoxbuster\\\\\\\\b\|\\\\\\\\bwfuzz\\\\\\\\b\|\\\\\\\\bjaeles\\\\\\\\b\|\\\\\\\\bzgrab2\?\\\\\\\\b\|\\\\\\\\bcommix\\\\\\\\b\|\\\\\\\\bxsstrike\\\\\\\\b\|\\\\\\\\bkiterunner\\\\\\\\b\|\(\?:\^\|[/]\)katana\(\?:/\|\\\\\\\\b\)\|\\\\\\\\bkr/\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"70\"][id\"338800\"][rev\"2\"][msg\"Atomicorp.comWAFRules:Blockedrecon/fuzzUA\"][severity\"CRITICAL\"][hostname\"dgtime.ch\"][uri\"/\"][unique_id\"al5v3wXoQGZ5kbMSrCvcKgAAAQw\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-07-20 11:35:05
(11 hours ago)
Automatic report - Vulnerability scan
/wordpress.zip
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-19 14:06:42
(1 day ago)
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:/batch/v ...
show more
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:/batch/v1
show less
Hacking
๐จ๐ด
adalbertoreyes.org
2026-07-18 18:22:53
(2 days ago)
CategoryPortScan
Port Scan
๐ฎ๐ฑ
spd.co.il
2026-07-04 01:02:16
(2 weeks ago)
Web application attack detected
Hacking
Web App Attack
๐บ๐ธ
rdpguard.com
2026-06-28 20:55:58
(3 weeks ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฎ๐น
Progetto1
2026-06-28 18:50:03
(3 weeks ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ญ
zynex
2026-06-21 17:52:52
(4 weeks ago)
URL Probing: /phpLogin.php
Web App Attack
๐ฉ๐ช
LRob
2026-06-09 20:30:04
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-07 13:05:06
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 62.72.5.52 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 62.72.5.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 09:04:58.770575 2026] [security2:error] [pid 963:tid 1019] [client 62.72.5.52:47864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||woodamy.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "woodamy.com"] [uri "/wp-content/backup-migration/complete_logs.log"] [unique_id "aiVsegZPtED5SKXlVylNTAAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 15:01:13
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 62.72.5.52 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 62.72.5.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 11:01:05.809769 2026] [security2:error] [pid 7268:tid 7292] [client 62.72.5.52:44208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||41bravo.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "41bravo.com"] [uri "/wp-content/backup-migration/complete_logs.log"] [unique_id "aiQ2MX1gcUPpjfksXw5-jgAAAdY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 14:51:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 62.72.5.52 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 62.72.5.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 10:50:57.366104 2026] [security2:error] [pid 8491:tid 8514] [client 62.72.5.52:59370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vinylnotespodcast.com"] [uri "/wp-config.php.save.1"] [unique_id "ahxK0c_MQazN-3hYhEuwUwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-05-29 11:37:22
(1 month ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 62.72.5.52 (US/United States/-): 2 in th ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 62.72.5.52 (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 62.72.5.52 - - [29/May/2026:13:37:19 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/2.0" 404 8100 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" host=frleone.ovh
62.72.5.52 - - [29/May/2026:13:37:19 +0200] "GET /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/2.0" 404 8103 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" host=frleone.ovh
show less
Port Scan
๐ฆ๐บ
MAGIC
2026-05-16 00:29:41
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ญ๐ฐ
Harold Wong
2026-04-30 03:57:25
(2 months ago)
$f2bV_matches
Brute-Force