|
๐ง๐ช
cmbplf
|
|
7.073 requests with url.path */xmlrpc.php
7.073 requests with url.path //xmlrpc.php
|
Brute-Force
Bad Web Bot
|
|
|
๐ฉ๐ช
LRob
|
|
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
|
Bad Web Bot
|
|
|
๐ต๐ฑ
nfsec.pl
|
|
85.203.45.55 - - [21/May/2026:10:50:24 +0000] "GET /templates/Protostar/error.php HTTP/2.0" 404 2388 ...
show more
85.203.45.55 - - [21/May/2026:10:50:24 +0000] "GET /templates/Protostar/error.php HTTP/2.0" 404 23887 "https://nfsec.pl//templates/Protostar/error.php" "Go-http-client/2.0"
85.203.45.55 - - [21/May/2026:10:50:25 +0000] "GET /modules/ets_whatsapp/security.php HTTP/2.0" 404 23948 "https://nfsec.pl//modules/ets_whatsapp/security.php" "Go-http-client/2.0"
85.203.45.55 - - [21/May/2026:10:50:25 +0000] "GET /templates/Atum/ HTTP/2.0" 404 23987 "https://nfsec.pl//templates/Atum/index.php" "Go-http-client/2.0"
85.203.45.55 - - [21/May/2026:10:50:26 +0000] "GET /components/com_newsfeeds/models/ HTTP/2.0" 404 23794 "https://nfsec.pl//components/com_newsfeeds/models/index.php" "Go-http-client/2.0"
85.203.45.55 - - [21/May/2026:10:50:26 +0000] "GET /templates/Eatoreh/ HTTP/2.0" 404 23952 "https://nfsec.pl//templates/Eatoreh/index.php" "Go-http-client/2.0"
...
show less
|
Web App Attack
Exploited Host
|
|
|
๐ฉ๐ช
ghostwarriors
|
|
Webpage scraping
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฎ๐น
alessio loto
|
|
WAF Detection: Security_Scanner_Blocked (Abusive IP). AI Confirmed Attack Payload.
|
Bad Web Bot
|
|
|
๐ซ๐ท
dynamix
|
|
WordPress XMLRPC Brute Force Attack
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ท
dynamix
|
|
WordPress XMLRPC Brute Force Attack
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
mnsf
|
|
Too many Status 40X (11)
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
BlueWire Hosting
|
|
Bad bot ignoring robot.txt
|
Bad Web Bot
|
|
|
๐ฌ๐ง
consul.to
|
|
Web attack/malicious scanning detected
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 85.203.45.55 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 16:03:26.258944 2026] [security2:error] [pid 30974:tid 30974] [client 85.203.45.55:29631] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intercotrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intercotrading.com"] [uri "/restore/sql.sql"] [unique_id "aZTXnpZUiJLCAlIVOmvnzQAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฏ๐ต
Valhalla
|
|
/wallets/log.txt
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 85.203.45.55 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 05:40:51.659842 2026] [security2:error] [pid 1562402:tid 1562446] [client 85.203.45.55:34967] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bluetigertees.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bluetigertees.com"] [uri "/restore/mysql.sql"] [unique_id "aYcWs1GHO4oC0Q2dQXD2lwAAAYo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 85.203.45.55 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 06:26:27.016163 2026] [security2:error] [pid 9834:tid 9834] [client 85.203.45.55:46857] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||asiabeef.network|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "asiabeef.network"] [uri "/backup/backup.sql"] [unique_id "aW9mYy7PqEVjweASB-zZvAAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
Penny Packer
|
|
Fail2Ban apache-tripwires
|
Web App Attack
|
|