๐จ๐ฆ
polycoda
2026-06-25 12:27:24
(2 months ago)
๐ฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
๐ซ๐ท
debaba
2026-04-12 04:20:39
(4 months ago)
[12/Apr/2026:04:20:36.883095 +0000] adsdlE6j1TFLWxAW8RP6vgAAAMk 91.180.221.15 54626 127.0.0.1 7081
[ ...
show more
[12/Apr/2026:04:20:36.883095 +0000] adsdlE6j1TFLWxAW8RP6vgAAAMk 91.180.221.15 54626 127.0.0.1 7081
[12/Apr/2026:04:20:36.961654 +0000] adsdlL3R3G3ls6F
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-12 03:04:18
(4 months ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ฎ
tjs
2026-04-05 22:45:00
(4 months ago)
web attack, SQL injection attempt
Hacking
SQL Injection
Web App Attack
๐ฏ๐ต
VXG-NET
2026-04-04 16:19:05
(4 months ago)
port=80, indicator_type=sql-injection
SQL Injection
๐น๐ผ
kk_it_man
2026-04-04 16:16:02
(4 months ago)
hack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-02 17:19:48
(4 months ago)
(mod_security) mod_security (id:210580) triggered by 91.180.221.15 (15.221-180-91.adsl-dyn.isp.belga ...
show more
(mod_security) mod_security (id:210580) triggered by 91.180.221.15 (15.221-180-91.adsl-dyn.isp.belgacom.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 13:19:44.263876 2026] [security2:error] [pid 19049:tid 19049] [client 91.180.221.15:51364] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:pid. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.powerkiteforum.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:pid: ../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.powerkiteforum.com"] [uri "/files.php"] [unique_id "ac6lMD05NjMjE4nRpJdWKQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
HeliJP
2026-04-02 16:45:34
(4 months ago)
2026-04-02T16:07:24Z - Recognized attacks\bad behavior from IP address 91.180.221.15 on port 443\80 ...
show more
2026-04-02T16:07:24Z - Recognized attacks\bad behavior from IP address 91.180.221.15 on port 443\80 (78 daily hits): SQL Injection Attack: SQL Tautology Detected, Detects classic SQL injection probings 2/3, SQLi bypass attempt by ticks detected, Possible XSS Attack Detected - HTML Tag Handler, XSS Filter - Category 1: Script Tag Vector, Multiple URL Encoding Detected, XSS Attack Detected via libinjection, OS File Access Attempt, Path Traversal Attack (/../), Remote Command Execution: Unix Shell Code Found, SQL Injection Attack: Common Injection Testing Detected, Detects classic SQL injection probings 1/3, NoScript XSS InjectionChecker: HTML Injection, Restricted File Access Attempt
show less
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-02 15:22:35
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
octageeks.com
2026-04-02 04:08:08
(4 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 00:38:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 91.180.221.15 (15.221-180-91.adsl-dyn.isp.belga ...
show more
(mod_security) mod_security (id:210492) triggered by 91.180.221.15 (15.221-180-91.adsl-dyn.isp.belgacom.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 20:38:28.400861 2026] [security2:error] [pid 25134:tid 25134] [client 91.180.221.15:63661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coffeewitheinstein.com"] [uri "/.env"] [unique_id "ac26hNNgjhY5i20g0jOhHgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
kk_it_man
2026-04-02 00:33:03
(4 months ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Script tag in URI Possible Cros ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Script tag in URI Possible Cross Site Scripting Attempt
show less
Port Scan
๐บ๐ธ
RidgeStar
2026-04-01 23:41:42
(4 months ago)
2026-04-01T16:41:41-07:00: <script>alert('XSS')</script>
2026-04-01T16:41:41-0 ...
show more
2026-04-01T16:41:41-07:00: <script>alert('XSS')</script>
2026-04-01T16:41:41-07:00: <script>alert('XSS')</script>
2026-04-01T16:41:40-07:00: <script>alert('XSS')</script>
2026-04-01T16:41:40-07:00: <script>alert('XSS')</script>
2026-04-01T16:41:40-07:00: <script>alert('XSS')</script>
show less
Port Scan
Hacking
Anonymous
2026-04-01 22:42:11
(4 months ago)
HTTPS vulnerability scan attempt detected. Port 443.
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-04-01 22:02:45
(4 months ago)
Login credentials theft attempt
Hacking