๐จ๐ญ
backslash
2025-10-04 02:10:14
(8 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2025-09-27 23:10:22
(8 months ago)
156.228.181.29 - - [27/Sep/2025:23:10:21 +0000] "\x16\x03\x01\x01C\x01" 400 392 "-" "-"
...
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-09-27 22:25:09
(8 months ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
Anonymous
2025-09-26 05:22:08
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Ad Ministrator
2025-09-25 08:20:12
(8 months ago)
RdpGuard detected brute-force attempt on RD-WEB
Brute-Force
๐ฉ๐ช
Ad Ministrator
2025-09-19 16:23:10
(8 months ago)
RdpGuard detected brute-force attempt on RD-WEB
Brute-Force
๐ญ๐บ
DumaNet
2025-09-17 23:50:00
(8 months ago)
WordPress (CMS) attack attempts.
Date: 2025 Sep 16. 07:27:18
Source IP: 156.228.181.29
Portion ...
show more
WordPress (CMS) attack attempts.
Date: 2025 Sep 16. 07:27:18
Source IP: 156.228.181.29
Portion of the log(s):
156.228.181.29 - [16/Sep/2025:07:26:02 +0200] "GET /site/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
156.228.181.29 - [16/Sep/2025:07:26:02 +0200] "GET /test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
156.228.181.29 - [16/Sep/2025:07:26:02 +0200] "GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
156.228.181.29 - [16/Sep/2025:07:26:02 +0200] "GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" ....
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 06:22:29
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.228.181.29 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.228.181.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 02:22:22.186021 2025] [security2:error] [pid 15454:tid 15454] [client 156.228.181.29:40663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ixd.net"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aL0knoR2WZVOrRX6dy-1swAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 05:53:49
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.228.181.29 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.228.181.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 01:53:42.681684 2025] [security2:error] [pid 9801:tid 9805] [client 156.228.181.29:31485] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lancasterdesignercraftsmen.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lancasterdesignercraftsmen.org"] [uri "/s3cmd.ini"] [unique_id "aL0d5ngGnwQPlRTC1GFJvQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 16:03:17
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.228.181.29 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.228.181.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 12:03:09.396178 2025] [security2:error] [pid 12945:tid 12945] [client 156.228.181.29:19877] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kairoslogammakmur.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kairoslogammakmur.com"] [uri "/s3cmd.ini"] [unique_id "aLxbPXoVmE0uKrzeARqoRwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-25 17:47:17
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฌ๐ง
Silly Development
2025-04-26 09:52:40
(1 year ago)
Malicious activity detected from 200373 DREI-K-TECH-GMBH towards host sillydev.co.uk (GET HTTP/2) @ ...
show more
Malicious activity detected from 200373 DREI-K-TECH-GMBH towards host sillydev.co.uk (GET HTTP/2) @ 2025-04-26T09:52:40Z (1 occurrences)
show less
DDoS Attack
Hacking
Exploited Host