๐ฐ๐ท
4.218.11.88
18 Sep 2025
(mod_security) mod_security (id:5000228) triggered by 4.218.11.88 (KR/South Korea/-): 1 in the last ...
show more
(mod_security) mod_security (id:5000228) triggered by 4.218.11.88 (KR/South Korea/-): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 19:07:06.830157 2025] [security2:error] [pid 2858827:tid 2858873] [client 4.218.11.88:0] ModSecurity: Access denied with code 411 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/apache2/conf.d/modsec2.rules.conf"] [line "61"] [id "5000228"] [msg "xmlrpc DoS attempt"] [hostname "mogbox.net"] [uri "/xmlrpc.php"] [unique_id "aMyQmvfLTM6C_QsUI4YfLwAAABA"]
show less
Hacking
๐จ๐ญ
107.189.6.137
18 Sep 2025
Web-based Attack: GET /wp-login.php?wp_lang=e HTTP/2.0
Hacking
Web App Attack
๐ณ๐ฑ
195.178.110.161
18 Sep 2025
(mod_security) mod_security (id:210492) triggered by 195.178.110.161 (BG/Bulgaria/-): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 195.178.110.161 (BG/Bulgaria/-): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 18:52:25.462744 2025] [security2:error] [pid 2859166:tid 2859191] [remote 195.178.110.161:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mogbox.net"] [uri "/.env"] [unique_id "aMyNKasTiYnkwneAcObtRQAAVBg"]
show less
Hacking
๐บ๐ธ
13.92.237.239
18 Sep 2025
(RSRCTROLL) Vulnerability Trolling: GET/POST /info.php 13.92.237.239 (US/United States/-): 1 in the ...
show more
(RSRCTROLL) Vulnerability Trolling: GET/POST /info.php 13.92.237.239 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 13.92.237.239 - - [18/Sep/2025:18:48:39 -0400] "GET /info.php HTTP/2.0" 200 12437 "-" "-"
show less
Hacking
๐บ๐ธ
40.85.189.190
18 Sep 2025
(RSRCTROLL) Vulnerability Trolling: GET/POST /info.php 40.85.189.190 (US/United States/-): 1 in the ...
show more
(RSRCTROLL) Vulnerability Trolling: GET/POST /info.php 40.85.189.190 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 40.85.189.190 - - [18/Sep/2025:18:28:31 -0400] "GET /info.php HTTP/2.0" 401 53 "-" "-"
show less
Hacking
๐บ๐ธ
34.73.98.110
18 Sep 2025
(RSRCTROLL) Vulnerability Trolling: HEAD /bk 34.73.98.110 (US/United States/110.98.73.34.bc.googleus ...
show more
(RSRCTROLL) Vulnerability Trolling: HEAD /bk 34.73.98.110 (US/United States/110.98.73.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.73.98.110 - - [18/Sep/2025:17:01:30 -0400] "HEAD /bk HTTP/2.0" 404 - "http://mogbox.net/bk" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:115.0) Gecko/20100101 Firefox/115.0"
show less
Hacking
๐บ๐ธ
212.28.179.24
18 Sep 2025
(mod_security) mod_security (id:210492) triggered by 212.28.179.24 (US/United States/vmi2300427.cont ...
show more
(mod_security) mod_security (id:210492) triggered by 212.28.179.24 (US/United States/vmi2300427.contaboserver.net): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 16:05:30.243799 2025] [security2:error] [pid 2858827:tid 2858840] [remote 212.28.179.24:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mogs.lol"] [uri "/.env"] [unique_id "aMxmCvfLTM6C_QsUI4YcwgAACgk"]
show less
Hacking
๐บ๐ธ
40.85.184.203
18 Sep 2025
Web-based Attack: GET /wp-login.php HTTP/2.0
Hacking
Web App Attack
๐จ๐ณ
49.232.151.112
18 Sep 2025
(mod_security) mod_security (id:210350) triggered by 49.232.151.112 (CN/China/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:210350) triggered by 49.232.151.112 (CN/China/-): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 15:31:37.621539 2025] [security2:error] [pid 2859166:tid 2859202] [client 49.232.151.112:47166] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.fitchugs.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.fitchugs.com"] [uri "/"] [unique_id "aMxeGasTiYnkwneAcObmdgAAAEk"]
show less
Hacking
๐ธ๐ช
188.148.49.251
18 Sep 2025
Web-based Attack: POST /xmlrpc.php HTTP/2.0
Hacking
Web App Attack
๐ฎ๐ณ
106.215.80.208
18 Sep 2025
Web-based Attack: POST /xmlrpc.php HTTP/2.0
Hacking
Web App Attack
๐ฏ๐ต
43.167.245.18
18 Sep 2025
(mod_security) mod_security (id:210350) triggered by 43.167.245.18 (JP/Japan/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:210350) triggered by 43.167.245.18 (JP/Japan/-): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 15:10:34.915946 2025] [security2:error] [pid 2858827:tid 2858862] [client 43.167.245.18:34522] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||srv.mogbox.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "srv.mogbox.net"] [uri "/"] [unique_id "aMxZKvfLTM6C_QsUI4Yb4AAAAAU"]
show less
Hacking
๐บ๐ธ
209.126.84.16
18 Sep 2025
(mod_security) mod_security (id:210492) triggered by 209.126.84.16 (US/United States/vmi2770517.cont ...
show more
(mod_security) mod_security (id:210492) triggered by 209.126.84.16 (US/United States/vmi2770517.contaboserver.net): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 15:10:25.325684 2025] [security2:error] [pid 2858827:tid 2858881] [client 209.126.84.16:64258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fitchugs.com"] [uri "/.env"] [unique_id "aMxZIffLTM6C_QsUI4Yb3AAAABg"]
show less
Hacking
๐บ๐ธ
204.44.100.55
18 Sep 2025
(mod_security) mod_security (id:225170) triggered by 204.44.100.55 (US/United States/204-44-100-55-h ...
show more
(mod_security) mod_security (id:225170) triggered by 204.44.100.55 (US/United States/204-44-100-55-host.colocrossing.com): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 14:45:16.623421 2025] [security2:error] [pid 2858827:tid 2858846] [remote 204.44.100.55:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mogbox.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mogbox.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aMxTPPfLTM6C_QsUI4YblgAADQ8"]
show less
Hacking
๐ซ๐ท
143.244.57.121
18 Sep 2025
(mod_security) mod_security (id:225170) triggered by 143.244.57.121 (FR/France/unn-143-244-57-121.da ...
show more
(mod_security) mod_security (id:225170) triggered by 143.244.57.121 (FR/France/unn-143-244-57-121.datapacket.com): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 13:46:53.086760 2025] [security2:error] [pid 2859166:tid 2859184] [remote 143.244.57.121:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mogbox.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mogbox.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aMxFjasTiYnkwneAcObkIgAAUxE"]
show less
Hacking
๐ฐ๐ท
4.218.13.231
18 Sep 2025
(RSRCTROLL) Vulnerability Trolling: GET/POST /wp.php 4.218.13.231 (KR/South Korea/-): 1 in the last ...
show more
(RSRCTROLL) Vulnerability Trolling: GET/POST /wp.php 4.218.13.231 (KR/South Korea/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 4.218.13.231 - - [18/Sep/2025:13:22:52 -0400] "GET /wp.php HTTP/2.0" 404 167 "-" "-"
show less
Hacking
๐ธ๐ช
94.247.172.129
18 Sep 2025
(mod_security) mod_security (id:210350) triggered by 94.247.172.129 (SE/Sweden/94-247-172-129-static ...
show more
(mod_security) mod_security (id:210350) triggered by 94.247.172.129 (SE/Sweden/94-247-172-129-static.serverhotell.net): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 13:02:43.947190 2025] [security2:error] [pid 2858827:tid 2858881] [client 94.247.172.129:47678] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.fitchugs.com|F|4"] [data "close, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.fitchugs.com"] [uri "/"] [unique_id "aMw7M_fLTM6C_QsUI4YaRwAAABg"]
show less
Hacking
๐บ๐ธ
170.106.180.139
18 Sep 2025
(mod_security) mod_security (id:210350) triggered by 170.106.180.139 (US/United States/-): 1 in the ...
show more
(mod_security) mod_security (id:210350) triggered by 170.106.180.139 (US/United States/-): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 18 12:37:22.846930 2025] [security2:error] [pid 2859166:tid 2859213] [client 170.106.180.139:52846] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||209.59.154.179:80|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "209.59.154.179"] [uri "/"] [unique_id "aMw1QqsTiYnkwneAcObiywAAAFQ"]
show less
Hacking
๐บ๐ธ
206.189.64.130
18 Sep 2025
(CBLTSTRK) Probing for Cobaltstrike beacon /ab2g 206.189.64.130 (US/United States/-): 1 in the last ...
show more
(CBLTSTRK) Probing for Cobaltstrike beacon /ab2g 206.189.64.130 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 206.189.64.130 - - [18/Sep/2025:12:32:56 -0400] "GET /ab2g HTTP/1.1" 301 20 "-" "Mozilla/5.0 zgrab/0.x"
show less
Hacking
๐จ๐ณ
2408:8240:631:e5d0:1a03:73ff:fef4:d058
18 Sep 2025
Web-based Attack: POST /xmlrpc.php HTTP/2.0
Hacking
Web App Attack
๐บ๐ธ
2604:a880:800:14:0:1:a252:9000
18 Sep 2025
Web-based Attack: POST /xmlrpc.php HTTP/2.0
Hacking
Web App Attack
๐บ๐ธ
13.90.18.197
18 Sep 2025
(RSRCTROLL) Vulnerability Trolling: GET/POST /info.php 13.90.18.197 (US/United States/-): 1 in the l ...
show more
(RSRCTROLL) Vulnerability Trolling: GET/POST /info.php 13.90.18.197 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 13.90.18.197 - - [18/Sep/2025:12:15:25 -0400] "GET /info.php HTTP/2.0" 404 167 "-" "-"
show less
Hacking
๐ญ๐ฐ
123.1.133.4
18 Sep 2025
Web-based Attack: POST /xmlrpc.php HTTP/2.0
Hacking
Web App Attack
๐ฉ๐ช
159.65.124.148
18 Sep 2025
Web-based Attack: POST /xmlrpc.php HTTP/2.0
Hacking
Web App Attack
๐ฎ๐ณ
165.22.223.164
18 Sep 2025
Web-based Attack: POST /xmlrpc.php HTTP/2.0
Hacking
Web App Attack