Anonymous
2026-07-16 11:01:19
(1 month ago)
2026-07-16 13:01:19 ERROR util.AccessViolations - 104.164.168.3 report to fail2ban - action: block
. ...
show more
2026-07-16 13:01:19 ERROR util.AccessViolations - 104.164.168.3 report to fail2ban - action: block
...
show less
Hacking
Brute-Force
Bad Web Bot
Anonymous
2026-06-14 06:57:26
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.164.168.3 (VN/Vietnam/-)
SQL Injection
๐จ๐ญ
backslash
2026-04-16 14:48:00
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
mnsf
2026-04-16 11:08:14
(4 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 11:06:26
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 104.164.168.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:234930) triggered by 104.164.168.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 07:06:20.215116 2026] [security2:error] [pid 8497:tid 8568] [client 104.164.168.3:40655] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||dcs.co.id|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "dcs.co.id"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aeDCrKXZ3odXK7H4gTmMiAAAAY4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-04-16 04:26:13
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mawan
2026-04-15 14:21:47
(4 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
oncord
2026-02-25 02:12:06
(6 months ago)
Form spam
Web Spam
๐ณ๐ฑ
homeshowdomain.nl
2026-02-23 23:01:00
(6 months ago)
Auto-ban: 22 malicious requests on 2026-02-22 (e.g., env/backup probes, brute-force, or error bursts ...
show more
Auto-ban: 22 malicious requests on 2026-02-22 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
consul.to
2026-02-23 08:47:34
(6 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-02-23 08:32:22
(6 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 04:08:24
(6 months ago)
(mod_security) mod_security (id:240000) triggered by 104.164.168.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 104.164.168.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 23:08:19.028075 2026] [security2:error] [pid 8096:tid 8096] [client 104.164.168.3:24705] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||icsubb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "icsubb.com"] [uri "/images/stories/themes.php"] [unique_id "aZvSsz1OFcEPe0tjz1wVWgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-23 02:26:18
(6 months ago)
[redacted] 104.164.168.3 - - [23/Feb/2026:03:26:09 +0100] "GET /wp-admin/css/colors/blue/rk2.php HTT ...
show more
[redacted] 104.164.168.3 - - [23/Feb/2026:03:26:09 +0100] "GET /wp-admin/css/colors/blue/rk2.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
[redacted] 104.164.168.3 - - [23/Feb/2026:03:26:10 +0100] "GET /wp-admin/css/colors/light/profile.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
[redacted] 104.164.168.3 - - [23/Feb/2026:03:26:12 +0100] "GET /wp-admin/user/wp-login.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36"
[redacted] 104.164.168.3 - - [23/Feb/2026:03:26:13 +0100] "GET /wp-content/uploads/admin.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.41
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 22:40:18
(6 months ago)
(mod_security) mod_security (id:240000) triggered by 104.164.168.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 104.164.168.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 17:40:12.392203 2026] [security2:error] [pid 18230:tid 18230] [client 104.164.168.3:48311] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||booksforpoets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "booksforpoets.com"] [uri "/images/stories/themes.php"] [unique_id "aZuFzOVlurqRZc49LK-WOgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bazter.pro
2026-02-14 23:59:09
(6 months ago)
Auto-Ban [2026-02-15 01:59:06]: Suspicious Datacenter (EGIHosting); DC: EGIHosting [Paths: 180] | De ...
show more
Auto-Ban [2026-02-15 01:59:06]: Suspicious Datacenter (EGIHosting); DC: EGIHosting [Paths: 180] | Details: Sensitive files/paths: /wp-admin/network/, /wp-admin/css/colors/sunrise/, /wp-admin/css/colors/ectoplasm/, /wp-admin/js/dist/, /wp-admin/js/widgets/ | 403 errors (1): /cgi-bin/ | Other paths: /admin/uploads/, /wp-admin/js/widgets/, /wp-content/upgrade/, /wp-admin/maint/, /wp-content/uploads/2024/, /wp-content/plugins/ubh/, /wp-admin/css/colors/blue/, /ALFA_DATA/alfacgiapi/, /wp-includes/SimplePie/XML/, /wp-content/uploads/
show less
Web App Attack