๐จ๐ญ
Origon
2026-09-16 12:36:56
(6 hours ago)
http-wordpress-scan - IP: 140.99.1.20 - time="2026-09-16T14:36:56+02:00" level=info msg="(555f66b4f ...
show more
http-wordpress-scan - IP: 140.99.1.20 - time="2026-09-16T14:36:56+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-wordpress-scan by ip 140.99.1.20 (AU/137409) : 4h ban on Ip 140.99.1.20" module=db
show less
Web App Attack
๐จ๐ญ
backslash
2026-09-16 10:42:05
(7 hours ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ฉ๐ช
EGP Abuse Dept
2026-09-16 08:06:39
(10 hours ago)
Scanning for web/db/file exploits on rkvvroosendaalwebshop.nl
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 01:11:05
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 140.99.1.20 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 140.99.1.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 21:10:58.447158 2026] [security2:error] [pid 10570:tid 10570] [client 140.99.1.20:63655] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||santaholidaycards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "santaholidaycards.com"] [uri "/images/stories/themes.php"] [unique_id "aoEOItkBd0PryNVXH01gVgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 04:45:57
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 140.99.1.20 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 140.99.1.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:45:47.617498 2026] [security2:error] [pid 2845335:tid 2845335] [client 140.99.1.20:34973] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||daveslawncare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "daveslawncare.com"] [uri "/images/stories/themes.php"] [unique_id "ambie5vYurE-_PrYvfu01gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-26 14:52:14
(1 month ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
Octopuce
2026-07-22 13:54:58
(1 month ago)
Aggressive web search of vulnerable pages: /.well-known/wincust.php /wp-admin/css/colors/light/alfa- ...
show more
Aggressive web search of vulnerable pages: /.well-known/wincust.php /wp-admin/css/colors/light/alfa-rex.php /wp-good.php /wp-includes/index.php ...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-07-10 18:27:30
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-10 11:28:15
(2 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ฉ๐ช
maxpower
2026-07-08 08:20:34
(2 months ago)
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 140.99.1.20 (AU/Australia/-): 1 in the last 3 ...
show more
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 140.99.1.20 (AU/Australia/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 140.99.1.20 - - [08/Jul/2026:10:20:32 +0200] "GET /lock360.php HTTP/1.1" 301 289 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" host=mail.notaiopanella.it
show less
Port Scan
๐ณ๐ฑ
DrLex0
2026-07-08 05:08:29
(2 months ago)
Distributed attack from multiple IPs in 140.99.1.0/24 range, poking for WordPress
140.99.1.20 80 - ...
show more
Distributed attack from multiple IPs in 140.99.1.0/24 range, poking for WordPress
140.99.1.20 80 - [08/Jul/2026:05:05:48 +0000] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 2383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0"
140.99.1.20 80 - [08/Jul/2026:05:06:22 +0000] "GET /wp-includes/theme-compat/about.php HTTP/1.1" 404 2383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
140.99.1.20 80 - [08/Jul/2026:05:07:53 +0000] "GET /wp-conflg.php HTTP/1.1" 404 2383 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
140.99.1.20 80 - [08/Jul/2026:05:08:29 +0000] "GET /wp-admin/maint/ HTTP/1.1" 404 2383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0"
show less
DDoS Attack
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-05-16 19:06:36
(3 months ago)
(wordpress) Failed wordpress login from 140.99.1.20 (AU/Australia/-): (CF_ENABLE)
Brute-Force
๐ฉ๐ช
DocNetzwerk
2026-04-01 23:58:02
(5 months ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 140.99.1.20 (AU/Australi ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 140.99.1.20 (AU/Australia/-)
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-03-03 22:59:51
(6 months ago)
Auto-ban: >3000 req/min op 2026-03-03
Web App Attack
SSH
Hacking
๐ท๐บ
sms.ru
2026-03-03 19:17:16
(6 months ago)
/wp-admin/css/autoload_classmap.php
Web App Attack