Anonymous
2026-09-04 06:40:01
(1 day ago)
suspicious request in access.log
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 04:43:57
(1 day ago)
cloudlinux2 fail2ban: 2026-09-04 06:39:14,029 fail2ban.actions [1594]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 06:39:14,029 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.156.31.47cloudlinux2 fail2ban: 2026-09-04 06:41:33,390 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.23.29.236cloudlinux2 fail2ban: 2026-09-04 06:41:43,830 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.201.198.56 - 2026-09-04 06:41:43cloudlinux2 fail2ban: 2026-09-04 06:42:31,473 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 3.88.141.70cloudlinux2 fail2ban: 2026-09-04 06:43:16,183 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 185.223.152.215 - 2026-09-04 06:43:14cloudlinux2 fail2ban: 2026-09-04 06:43:32,282 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 100.31.58.163 - 2026-09-04 06:43:32cloudlinux2 fail2ban: 2026-09-04 06:43:32,539 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 100.31.58.163 - 2026-09-04 06:43:32cloudlinux2 fail2ban: 2026-09-04 06:43:32,760 fail2ban.filter
show less
Web App Attack
🇲🇽
octageeks.com
2026-09-04 04:20:47
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2026-09-04 03:31:07
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-04 02:45:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
Quarks Solutions
2026-09-04 01:50:53
(1 day ago)
crowdsecurity/appsec-vpatch
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:35:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 100.31.58.163 (ec2-100-31-58-163.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.58.163 (ec2-100-31-58-163.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:35:00.604242 2026] [security2:error] [pid 19383:tid 19383] [client 100.31.58.163:55576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeanboomergrenier.com"] [uri "/.git/config"] [unique_id "apogRKxVkqyZ-GLq6jNN4gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
lolyay
2026-09-04 01:28:50
(1 day ago)
100.31.58.163 - - [04/Sep/2026:01:28:48 +0000] "GET /.git/config HTTP/1.1" 200 4 "-" "Mozilla/5.0 (M ...
show more
100.31.58.163 - - [04/Sep/2026:01:28:48 +0000] "GET /.git/config HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
100.31.58.163 - - [04/Sep/2026:01:28:49 +0000] "GET /.env HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
🇵🇱
strefapi_com
2026-09-03 22:33:14
(1 day ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-09-03 21:45:32
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: panel.definitelynotahoneypot.online | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack