Anonymous
2026-07-10 00:37:05
(2 months ago)
"GET /wp-includes/blocks/about.php HTTP/1.1"
Hacking
Web App Attack
Anonymous
2026-07-09 22:37:04
(2 months ago)
Web Server Enforcement Violation.
Hacking
🇩🇰
ScamAware
2026-07-09 22:35:49
(2 months ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
🇨🇦
SSH-Admin
2026-07-09 21:41:34
(2 months ago)
Probing for Exploits on ns153
Exploited Host
Web App Attack
🇺🇸
ipblock.com
2026-07-09 20:36:00
(2 months ago)
IPBlock protected site ID [4055-d][s=01].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-07-09 20:28:03
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-07-09 15:25:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 11:24:55.484856 2026] [security2:error] [pid 2469:tid 2469] [client 64.112.57.167:49687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.albertmassaad.com"] [uri "/.env.prod"] [unique_id "ak-9RwLbWhwXc2A2FVkokQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-07-09 14:57:15
(2 months ago)
IM360 WAF: Interaction with fake plugin MV:/wp-content/plugins/WordPressCore/
Web App Attack
🇺🇸
ipblock.com
2026-07-09 10:16:00
(2 months ago)
IPBlock protected site ID [4055-d][s=01].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-09 08:19:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 04:18:51.787430 2026] [security2:error] [pid 14450:tid 14450] [client 64.112.57.167:49569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrbaystreet.com"] [uri "/.env.dev"] [unique_id "ak9Za634nCz5l5zZA4_fRQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-09 04:18:43
(2 months ago)
(mod_security) mod_security (id:211190) triggered by 64.112.57.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 64.112.57.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 00:18:16.337471 2026] [security2:error] [pid 28764:tid 28947] [client 64.112.57.167:38491] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.adultbaja.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_gcalendar&controller=../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adultbaja.com"] [uri "/index.php"] [unique_id "ak8hCPOvMKT8-UyubSD1LAAAAdg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-07-08 23:42:50
(2 months ago)
🥶 Part of a DDoS attack wave
DDoS Attack
🇨🇦
polycoda
2026-07-08 21:48:26
(2 months ago)
🥶 Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
🇺🇸
TPI-Abuse
2026-07-08 19:22:30
(2 months ago)
(mod_security) mod_security (id:220150) triggered by 64.112.57.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:220150) triggered by 64.112.57.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 15:22:21.547589 2026] [security2:error] [pid 5233:tid 5233] [client 64.112.57.167:55421] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:listingID. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||www.oualierealty.com|F|2"] [data "352')/**/union/**/select/**/null,null,null,null,null,null,null,null,null,null,null,null,null,null,'qscan_union_20_14',null,null,null,null,null--qscan"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.oualierealty.com"] [uri "/index.php"] [unique_id "ak6jbQuk41_5clCM1O8gzgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
OK
2026-07-08 17:06:28
(2 months ago)
HTTP/HTTPS
Hacking
Web App Attack