๐ซ๐ท
SpaceHost-Server
2026-07-19 22:27:10
(1 day ago)
Brute-Force
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-19 06:00:00
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ง๐ช
taivas.nl
2026-07-19 04:32:20
(2 days ago)
Many_bad_calls
Web App Attack
๐ซ๐ฎ
YF
2026-07-19 01:00:25
(2 days ago)
WordPress content enumeration
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-07-19 00:02:47
(2 days ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-07-18 23:16:11
(2 days ago)
Web attack blocked by Wordfence on limburgsekunstkring.nl (9 hits). Reported by CRMON.
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-18 21:45:00
(2 days ago)
[Sun Jul 19 07:44:59.133649 2026] [security2:error] [pid 834114] [client 158.173.77.162:22453] [clie ...
show more
[Sun Jul 19 07:44:59.133649 2026] [security2:error] [pid 834114] [client 158.173.77.162:22453] [client 158.173.77.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/wp-plain.php"] [unique_id "alvz23dCpg_Aw4bvT7gmkAAAAAY"], referer: www.google.com
...
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-18 21:26:43
(2 days ago)
[Sun Jul 19 07:26:42.210773 2026] [security2:error] [pid 829606] [client 158.173.77.162:48925] [clie ...
show more
[Sun Jul 19 07:26:42.210773 2026] [security2:error] [pid 829606] [client 158.173.77.162:48925] [client 158.173.77.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "shotbysuzanne.com.au"] [uri "/wp-plain.php"] [unique_id "alvvkn7HWszEE8I-APyH3gAAAAA"], referer: www.google.com
...
show less
Web App Attack
๐ฌ๐ท
setupgr
2026-07-18 21:23:59
(2 days ago)
(mod_security) mod_security (id:1000001) triggered by 158.173.77.162 (IT/Italy/Lombardy/Milan/-/[AS2 ...
show more
(mod_security) mod_security (id:1000001) triggered by 158.173.77.162 (IT/Italy/Lombardy/Milan/-/[AS206092 SECFIREWALLAS]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Jul 19 00:23:56.158257 2026] [security2:error] [pid 1251043:tid 1251182] [client 158.173.77.162:41267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/seotheme/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "asteriassantorini.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "alvu7I99CdQQk64KARPLrwAAAsY"], referer: www.google.com
show less
Port Scan
Anonymous
2026-07-18 19:27:44
(2 days ago)
[ns31.kdns.gr] httpd-suspicious-path: sites=www.myrofores.gr; logs=/var/log/httpd/domains/myrofores. ...
show more
[ns31.kdns.gr] httpd-suspicious-path: sites=www.myrofores.gr; logs=/var/log/httpd/domains/myrofores.gr.log; samples=/ALFA_DATA/alfacgiapi/perl.alfa | /wp-content/themes/seotheme/db.php?u | /wp-content/plugins/fix/up.php
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-07-18 19:02:09
(2 days ago)
Bad_requests
Bad Web Bot
๐ฉ๐ช
MarkGGN
2026-07-18 19:01:31
(2 days ago)
Web attack. 158.173.77.162 - - [18/Jul/2026:21:01:30 +0200] "GET /wp-content/plugins/fix/up.php HTTP ...
show more
Web attack. 158.173.77.162 - - [18/Jul/2026:21:01:30 +0200] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
158.173.77.162 - - [18/Jul/2026:21:01:30 +0200] "GET /wp-content/plugins/apikey/apikey.php?test=hello HTTP/1.1" 403 548 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
show less
Web App Attack
๐ฎ๐น
mediarama.com
2026-07-18 17:51:10
(2 days ago)
Banned by Fail2Ban
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-07-18 16:52:50
(2 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ฉ๐ช
LRob
2026-07-18 16:07:08
(2 days ago)
CrowdSec: crowdsecurity/http-bad-user-agent | req: /barometre/ALFA_DATA/alfacgiapi/perl.alfa | 2 dis ...
show more
CrowdSec: crowdsecurity/http-bad-user-agent | req: /barometre/ALFA_DATA/alfacgiapi/perl.alfa | 2 distinct paths | UA: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.
show less
Bad Web Bot