๐ซ๐ฎ
sibahota
2026-09-27 18:51:10
(16 hours ago)
8.138.224.48 - - [27/Sep/2026:18:51:08 +0000] jntjewellers.com "GET /plug/oem/load.gif HTTP/1.1" 404 ...
show more
8.138.224.48 - - [27/Sep/2026:18:51:08 +0000] jntjewellers.com "GET /plug/oem/load.gif HTTP/1.1" 404 197 0.001 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" 172.17.0.1:8080 404 0.000 "http://jntjewellers.com/plug/oem/load.gif"
8.138.224.48 - - [27/Sep/2026:18:51:08 +0000] jntjewellers.com "GET /static/warn/close.php HTTP/1.1" 404 197 0.001 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" 172.17.0.1:8080 404 0.000 "http://jntjewellers.com/static/warn/close.php"
8.138.224.48 - - [27/Sep/2026:18:51:08 +0000] jntjewellers.com "GET /includes/cls_sms.php HTTP/1.1" 404 197 0.001 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" 172.17.0.1:8080 404 0.001 "http://jntjewellers.com/includes/cls_sms.php"
8.138.224.48 - - [27/Sep/2026:18:51:08 +0000] jntjewellers.com "GET /data/captcha/captcha
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 16:58:08
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.138.224.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 8.138.224.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 12:58:04.067185 2026] [security2:error] [pid 2116:tid 2116] [client 8.138.224.48:48164] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iworklife.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iworklife.org"] [uri "/okok.cer"] [unique_id "arlLHPoSNX52-BqeYTJ2kgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
creoline GmbH
2026-09-27 01:22:22
(1 day ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-26 15:04:19
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
consul.to
2026-09-25 22:41:50
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-23 10:03:53
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
spot
2026-09-23 09:21:52
(5 days ago)
8.138.224.48 - - [23/Sep/2026:10:21:51 +0100] "GET /basic.bak.php HTTP/1.1" 404 341 "-" "Mozilla/5.0 ...
show more
8.138.224.48 - - [23/Sep/2026:10:21:51 +0100] "GET /basic.bak.php HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
๐ฉ๐ช
23p02732
2026-09-23 03:28:17
(5 days ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
pusathosting.com
2026-09-22 17:10:06
(5 days ago)
24ds22 bruteforce
Brute-Force
Web App Attack
๐บ๐ธ
Matthew Ping
2026-09-17 00:30:02
(1 week ago)
Excessive connections (DDoS/flood) blocked by CSF CT_LIMIT on wp1.
DDoS Attack
Brute-Force
๐ซ๐ท
regishoussin
2026-09-17 00:01:31
(1 week ago)
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-17 00:01 UTC.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:52:52
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 8.138.224.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 8.138.224.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:52:45.894129 2026] [security2:error] [pid 26577:tid 26577] [client 8.138.224.48:51462] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||arroceraomoa.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arroceraomoa.com"] [uri "/okok.cer"] [unique_id "aqqRHThD6HEG4R9PXDoHOQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-15 20:15:35
(1 week ago)
8.138.224.48 - - [15/Sep/2026:16:15:33 -0400] "GET /shell.php HTTP/1.1" 301 4829 "-" "Mozilla/5.0 (W ...
show more
8.138.224.48 - - [15/Sep/2026:16:15:33 -0400] "GET /shell.php HTTP/1.1" 301 4829 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
8.138.224.48 - - [15/Sep/2026:16:15:33 -0400] "GET /debug.php HTTP/1.1" 301 4829 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
8.138.224.48 - - [15/Sep/2026:16:15:34 -0400] "GET /shell.php HTTP/1.1" 404 33536 "https://anvisalarmllc.com/shell.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-13 22:30:13
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 22:18:48
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 8.138.224.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 8.138.224.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:18:40.854591 2026] [security2:error] [pid 18512:tid 18512] [client 8.138.224.48:58362] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||akramansari.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "akramansari.com"] [uri "/okok.cer"] [unique_id "aqchQPxnm1KlRVslNWvrwgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack