π¬π§
consul.to
2026-06-20 04:57:10
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
π¨π¦
dispensight
2026-06-19 12:16:32
(1 day ago)
SSL log traffic to dispensight.com: 1 req(s). URIs: /?rest_route=/wp/v2/users. UA: Mozilla/5.0 (Wind ...
show more
SSL log traffic to dispensight.com: 1 req(s). URIs: /?rest_route=/wp/v2/users. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64. Flag: known exploit/credential probe path.
show less
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-06-18 23:57:53
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π©πͺ
LRob.fr
2026-06-18 06:45:06
(3 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
π¬π§
andypiper
2026-06-18 01:01:32
(3 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
π©πͺ
maxpower
2026-06-18 00:14:32
(3 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 103.125.146.32 (JP/Japan/-): 3 in the last 360 ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 103.125.146.32 (JP/Japan/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 103.125.146.32 - - [18/Jun/2026:02:13:35 +0200] "POST /xmlrpc.php HTTP/1.1" 404 157659 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0" "-" host=ramsesconsulting.it
103.125.146.32 - - [18/Jun/2026:02:13:41 +0200] "POST /xmlrpc.php HTTP/1.1" 404 158293 "-" "Mozilla/5.0 (Linux; Android 11; Nokia G50) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.61 Mobile Safari/537.36" "-" host=ramsesconsulting.it
103.125.146.32 - - [18/Jun/2026:02:14:29 +0200] "POST /xmlrpc.php HTTP/1.1" 404 158516 "-" "Mozilla/5.0 (Linux; Android 11; Nokia G50) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.61 Mobile Safari/537.36" "-" host=ramsesconsulting.it
show less
Port Scan
π¬π·
setupgr
2026-06-16 11:25:52
(4 days ago)
(mod_security) mod_security (id:1000001) triggered by 103.125.146.32: 1 in the last 86400 secs; Port ...
show more
(mod_security) mod_security (id:1000001) triggered by 103.125.146.32: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Tue Jun 16 14:25:47.360154 2026] [security2:error] [pid 2210293:tid 2210394] [client 103.125.146.32:48325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp-load.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "93"] [id "1000001"] [msg "Bad file blocked: /wp-includes/SimplePie/wp-load.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.setworldup.com"] [uri "/wp-includes/SimplePie/wp-load.php"] [unique_id "ajEyu9Mtn8QwdXQy9m4sogAAAUw"]
show less
Port Scan
π¬π·
setupgr
2026-06-16 07:49:17
(5 days ago)
(mod_security) mod_security (id:1000001) triggered by 103.125.146.32: 1 in the last 86400 secs; Port ...
show more
(mod_security) mod_security (id:1000001) triggered by 103.125.146.32: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Tue Jun 16 10:49:16.665326 2026] [security2:error] [pid 2210176:tid 2210254] [client 103.125.146.32:53057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/ioxi-o.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "93"] [id "1000001"] [msg "Bad file blocked: /ioxi-o.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.sea-sound.com"] [uri "/ioxi-o.php"] [unique_id "ajD__I0pb6dkgQfaMdBghQAAAQU"]
show less
Port Scan
π¬π·
setupgr
2026-06-16 01:36:39
(5 days ago)
(mod_security) mod_security (id:1000001) triggered by 103.125.146.32: 1 in the last 86400 secs; Port ...
show more
(mod_security) mod_security (id:1000001) triggered by 103.125.146.32: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Tue Jun 16 04:36:37.077981 2026] [security2:error] [pid 1917012:tid 1917147] [client 103.125.146.32:37375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp-content/admin.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "92"] [id "1000001"] [msg "Bad file blocked: /wp-content/admin.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.pankoskal.gr"] [uri "/wp-content/admin.php"] [unique_id "ajCopUCXHuxGK7C8F7pAEgAAAFA"]
show less
Port Scan
π©πͺ
LRob.fr
2026-06-13 19:45:04
(1 week ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
π¦πΊ
paulshipley.com.au
2026-06-13 13:26:17
(1 week ago)
dlcarterauthor.com:443 103.125.146.32 - - [13/Jun/2026:23:26:15 +1000] "GET /item.php HTTP/1.1" 404 ...
show more
dlcarterauthor.com:443 103.125.146.32 - - [13/Jun/2026:23:26:15 +1000] "GET /item.php HTTP/1.1" 404 67606 "http://dlcarterauthor.com/item.php" "Go-http-client/1.1"
...
show less
Web App Attack
Anonymous
2026-06-13 13:18:46
(1 week ago)
Banned by Fail2Ban on server
Web App Attack
π©πͺ
Ba-Yu
2026-06-13 02:54:50
(1 week ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
π³π±
BlueWire Hosting
2026-06-12 16:24:00
(1 week ago)
Probing websites for vulnerabilities
Web App Attack
π«π·
masterguru
2026-06-11 06:43:12
(1 week ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-195)
show less
Bad Web Bot