๐ฎ๐ฉ
soc-yk
2026-07-22 18:06:10
(1 hour ago)
Type: suspicious_network_activity
Risk: 100
Events: 14
Evidence:
- Persistent suspicious network ac ...
show more
Type: suspicious_network_activity
Risk: 100
Events: 14
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Threat escalation behavior observed
show less
Port Scan
Hacking
๐ฉ๐ช
FeG Deutschland
2026-07-22 17:53:39
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฌ๐ง
Apache
2026-07-22 17:46:51
(2 hours ago)
(mod_security) mod_security (id:218580) triggered by 64.181.197.120 (US/United States/-): 5 in the l ...
show more
(mod_security) mod_security (id:218580) triggered by 64.181.197.120 (US/United States/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 16:44:37
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 13:17:38
(6 hours ago)
(mod_security) mod_security (id:218580) triggered by 64.181.197.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 64.181.197.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:17:29.995299 2026] [security2:error] [pid 862116:tid 862116] [client 64.181.197.120:57938] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:author_exclude. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||ac.cloudex.link|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "ac.cloudex.link"] [uri "/"] [unique_id "amDC6WsTltF7W-s9Mf0afQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-07-22 02:20:01
(17 hours ago)
Imunify360 WAF block (graylisted)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 01:05:47
(18 hours ago)
(mod_security) mod_security (id:218580) triggered by 64.181.197.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 64.181.197.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 21:05:41.945001 2026] [security2:error] [pid 679129:tid 679129] [client 64.181.197.120:47166] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:author_exclude. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||theseventhcongregationofladderdayvixens.org.tortoisehosting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "theseventhcongregationofladderdayvixens.org.tortoisehosting.com"] [uri "/"] [unique_id "amAXZb7pxRnsQ24ebcet0gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-21 14:13:08
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-21 13:42:25
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 10:46:18
(1 day ago)
(mod_security) mod_security (id:218580) triggered by 64.181.197.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 64.181.197.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:46:11.092783 2026] [security2:error] [pid 10514:tid 10514] [client 64.181.197.120:50894] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:author_exclude. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||glendaleheritage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "glendaleheritage.org"] [uri "/"] [unique_id "al9N8471GjX93nRw4B26tAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
0xffffffff
2026-07-21 05:37:07
(1 day ago)
[2026-07-21 08:37:04.815751] [authz_core:error] [pid 678963:tid 124364166440640] [client 64.181.197. ...
show more
[2026-07-21 08:37:04.815751] [authz_core:error] [pid 678963:tid 124364166440640] [client 64.181.197.120:0] AH01630: client denied by server configuration: /var/www/*/ , error_notes:wp-rest:user-enum , URI:'/?rest_route=/wp/v2/users&author_exclude=0%29%20AND%20%281%3D1%29--%20-'
[2026-07-21 08:37:05.133878] [authz_core:error] [pid 678963:tid 124364057122496] [client 64.181.197.120:0] AH01630: client denied by server configuration: /var/www/*/ , error_notes:wp-rest:user-enum , URI:'/?rest_route=/wp/v2/users&author_exclude=0%29AND%281%3D1%29--%20-'
[2026-07-21 08:37:05.491382] [authz_core:error] [pid 678964:tid 124364158031552] [client 64.181.197.120:0] AH01630: client denied by server configuration: /var/www/*/ , error_notes:wp-rest:user-enum , URI:'/?rest_route=/wp/v2/users&author_exclude=0%29%20%2F%2A%21AND%2A%2F%20%281%3D1%29--%20-'
[2026-07-21 08:37:05.607946] [authz_core:error] [pid 678963:tid 124364040304320] [client 64.181.197.120:0] AH01630: client denied by server configuration: /var/www/*/ , error_not
show less
Web App Attack
Bad Web Bot
Anonymous
2026-07-21 01:07:04
(1 day ago)
Banned by Fail2Ban on server
Web App Attack
๐ฎ๐น
mediarama.com
2026-07-20 23:37:48
(1 day ago)
Banned by Fail2Ban
Web App Attack
๐ซ๐ท
masterguru
2026-07-20 17:47:34
(2 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-193 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-193)
show less
Bad Web Bot
Anonymous
2026-07-20 16:33:17
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 64.181.197.120 (US/United States/-)
SQL Injection