๐ฌ๐ง
blik2108
2026-09-18 19:29:31
(23 hours ago)
72.62.124.240 - - [18/Sep/2026:19:29:28 +0000] "POST /index.php?option=com_sppagebuilder&task=asset. ...
show more
72.62.124.240 - - [18/Sep/2026:19:29:28 +0000] "POST /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon HTTP/1.1" 403 119 "-" "Mozilla/5.0 (X11; Linux x86_64) SP-Scanner" "-"
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-18 15:07:07
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 10:17:09
(2 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /accounts.txt | 2026-09-17 10:17 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-17 09:03:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:03:17.410938 2026] [security2:error] [pid 4136:tid 4136] [client 72.62.124.240:54706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abundancecompany.com"] [uri "/.env.backup"] [unique_id "aqus1dYS9ssEqDgghJiKSgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 08:23:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210730) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:23:51.224678 2026] [security2:error] [pid 18515:tid 18557] [client 72.62.124.240:36256] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aclarityforensics.com|F|2"] [data ".php.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aclarityforensics.com"] [uri "/config.php.backup"] [unique_id "aqujl_HIRHmcXWoi3KQIXAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-17 06:11:25
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:03:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:03:28.688361 2026] [security2:error] [pid 18159:tid 18159] [client 72.62.124.240:60430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achildsspace.com"] [uri "/.env.bak"] [unique_id "aquCsKW7l6RRQqEGBeF-jAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dwmp
2026-09-17 02:46:39
(2 days ago)
[17/Sep/2026:04:45:57.369902 +0200] aqtUZUebw4a9344QjvAHuAAAAJQ 72.62.124.240 47456 38.242.227.117 7 ...
show more
[17/Sep/2026:04:45:57.369902 +0200] aqtUZUebw4a9344QjvAHuAAAAJQ 72.62.124.240 47456 38.242.227.117 7081
[17/Sep/2026:04:46:36.190588 +0200] aqtUjOpQCkYDStCVAYWLYgAAAEY 72.62.124.240 53446 38.242.227.117 7081
[17/Sep/2026:04:46:38.802379 +0200] aqtUjkebw4a9344QjvAHuQAAAIc 72.62.124.240 55808 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-09-16 22:00:19
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-16
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 20:32:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 16:32:13.883306 2026] [security2:error] [pid 29467:tid 29467] [client 72.62.124.240:38208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityengraving.com"] [uri "/wp-config.php.bak"] [unique_id "aqr8zX1sD69oogRAnMawMwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-16 19:54:07
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:59:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:59:45.264327 2026] [security2:error] [pid 29771:tid 29771] [client 72.62.124.240:60470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abeltours.com"] [uri "/wp-config.php.backup"] [unique_id "aqrLARq-qx7_XimipS8a6AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:29:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 72.62.124.240 (srv1239121.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:29:03.410463 2026] [security2:error] [pid 24257:tid 24257] [client 72.62.124.240:57422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abcollie.com"] [uri "/wp-config.php.bak"] [unique_id "aqqnrzaBElDAOtdMMvmVlAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-16 10:30:12
(3 days ago)
72.62.124.240 - - [16/Sep/2026:12:30:08 +0200] "GET /config.php.bak HTTP/1.1" 302 503 "-" "Mozilla/5 ...
show more
72.62.124.240 - - [16/Sep/2026:12:30:08 +0200] "GET /config.php.bak HTTP/1.1" 302 503 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
72.62.124.240 - - [16/Sep/2026:12:30:10 +0200] "GET /config.php.bak HTTP/1.1" 301 5820 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
72.62.124.240 - - [16/Sep/2026:12:30:11 +0200] "GET /config.php.bak HTTP/1.1" 302 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 09:07:21
(3 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /register/ (+1 more) | 2026-09-16 09:07 UTC
show less
Bad Web Bot