๐บ๐ธ
TPI-Abuse
2026-09-03 09:09:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 116.203.190.67 (static.67.190.203.116.clients.y ...
show more
(mod_security) mod_security (id:210492) triggered by 116.203.190.67 (static.67.190.203.116.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:09:09.203329 2026] [security2:error] [pid 26455:tid 26455] [client 116.203.190.67:41360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lexie.boens.org"] [uri "/.hg/store/00manifest.i"] [unique_id "apk5NeATkcmx8fqdmsBVWwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Celtic
2026-09-03 08:53:10
(2 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐ญ๐บ
miszterx.hu
2026-09-03 07:15:40
(3 hours ago)
XORP (haproxy): 152x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_i ...
show more
XORP (haproxy): 152x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ณ๐ฑ
SysAdmin Dylan
2026-09-03 07:09:43
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 116.203.190.67 (DE/Germany/static.67.190.203.11 ...
show more
(mod_security) mod_security (id:210492) triggered by 116.203.190.67 (DE/Germany/static.67.190.203.116.clients.your-server.de): 10 in the last 3600 secs
show less
Brute-Force
๐ณ๐ฑ
Joop
2026-09-03 06:38:56
(4 hours ago)
2026-09-03 08:38:55 +0200 s17 /config.inc.php
Web App Attack
๐ซ๐ท
dynamix
2026-09-03 05:33:00
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-09-03 04:55:23
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ซ๐ท
Omar Martรญnez
2026-09-03 03:17:29
(7 hours ago)
116.203.190.67 - - [02/Sep/2026:21:17:28 -0600] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 7298 "-" ...
show more
116.203.190.67 - - [02/Sep/2026:21:17:28 -0600] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 7298 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Phishing
Email Spam
Blog Spam
๐ฉ๐ช
ghostwarriors
2026-09-02 20:50:08
(14 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-02 20:40:50
(14 hours ago)
116.203.190.67 - - [02/Sep/2026:22:40:46 +0200] "GET / HTTP/1.1" 302 4609 "-" "Mozilla/5.0 (Windows ...
show more
116.203.190.67 - - [02/Sep/2026:22:40:46 +0200] "GET / HTTP/1.1" 302 4609 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
116.203.190.67 - - [02/Sep/2026:22:40:46 +0200] "GET /blogg/ HTTP/1.1" 301 4665 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
116.203.190.67 - - [02/Sep/2026:22:40:46 +0200] "GET /blogg/ HTTP/1.1" 200 35501 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
116.203.190.67 - - [02/Sep/2026:22:40:46 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 4488 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
116.203.190.67 - - [02/Sep/2026:22:40:46 +0200] "POST /wp-json/batch/v1 HTTP/1.1" 403 4488 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Saf
show less
Web App Attack
Hacking
๐ฉ๐ช
msavo
2026-09-02 18:45:09
(16 hours ago)
CIR Sentinel: batch_auth_failures; 4 requests in 60s; targets=/?rest_route=/batch/v1, /index.php/wp- ...
show more
CIR Sentinel: batch_auth_failures; 4 requests in 60s; targets=/?rest_route=/batch/v1, /index.php/wp-json/batch/v1, /index.php?rest_route=/batch/v1, /wp-json/batch/v1; permanently blocked by the firewall.
show less
Web App Attack
๐ญ๐บ
kranem
2026-09-02 15:00:13
(20 hours ago)
Triggered Cloudflare WAF from DE.
Action taken: LINK_MAZE_INJECTED
ASN: 24940 (Hetzner Online GmbH)
...
show more
Triggered Cloudflare WAF from DE.
Action taken: LINK_MAZE_INJECTED
ASN: 24940 (Hetzner Online GmbH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-02T14:14:22Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-02 12:14:19
(22 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ช
taivas.nl
2026-09-02 07:02:11
(1 day ago)
Bad_requests
Bad Web Bot
๐ท๐บ
DZBOT
2026-09-02 06:42:31
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack