🇦🇺
paulshipley.com.au
2026-09-14 03:35:45
(28 minutes ago)
[Mon Sep 14 13:35:44.719846 2026] [security2:error] [pid 63836] [client 169.58.140.171:41314] [clien ...
show more
[Mon Sep 14 13:35:44.719846 2026] [security2:error] [pid 63836] [client 169.58.140.171:41314] [client 169.58.140.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellagiftware.com.au"] [uri "/index.php/jk"] [unique_id "aqdrkJMU8ZSMljVq_7L7CAAAAAY"]
...
show less
Web App Attack
🇫🇷
Tilellit.PRO
2026-09-14 03:04:12
(1 hour ago)
Malicious web traffic detected by CrowdSec
Hacking
🇹🇷
eryilmaz
2026-09-14 02:00:20
(2 hours ago)
Automated attack blocked by eryilmaz WAF/fail2ban: 1 event(s) [waf.block] in the last 1 days, e.g. / ...
show more
Automated attack blocked by eryilmaz WAF/fail2ban: 1 event(s) [waf.block] in the last 1 days, e.g. /jk
show less
Web App Attack
Hacking
🇫🇷
LRob
2026-09-14 01:18:10
(2 hours ago)
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show more
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 zgrab/0.x | path: /index.php/jk | 2026-09-14 01:18 UTC
show less
Bad Web Bot
🇺🇸
etu brutus
2026-09-14 01:11:03
(2 hours ago)
169.58.140.171 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
🇹🇷
oalver
2026-09-14 01:07:07
(2 hours ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_ua_signatu ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_ua_signature. Sources: nginx. Details: ua_signature: request to /index.php/jk (HTTP 301). First seen: 2026-08-07. Risk score: 36/100.
show less
Web App Attack
🇩🇪
sverson
2026-09-14 00:36:22
(3 hours ago)
Unauthorized login attempts
Brute-Force
🇦🇺
paulshipley.com.au
2026-09-14 00:36:08
(3 hours ago)
[Mon Sep 14 10:36:07.875690 2026] [security2:error] [pid 47030] [client 169.58.140.171:33832] [clien ...
show more
[Mon Sep 14 10:36:07.875690 2026] [security2:error] [pid 47030] [client 169.58.140.171:33832] [client 169.58.140.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "iaki.com.au"] [uri "/index.php/jk"] [unique_id "aqdBd0L5xblmc4KnAuOa-wAAAAE"]
...
show less
Web App Attack
Anonymous
2026-09-14 00:24:22
(3 hours ago)
Blocked by ModSec and CSF
Port Scan
🇪🇸
el-brujo
2026-09-14 00:19:24
(3 hours ago)
14/Sep/2026:02:19:24.099040 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
14/Sep/2026:02:19:24.099040 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 169.58.140.171] ModSecurity: Warning. Match of "rx ^urlgrabber/[0-9\\\\\\\\.]+ yum/[0-9\\\\\\\\.]+$" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "53"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "hostench.eu"] [uri "/index.php/jk"] [unique_id "aqc9jI7zxrfTdq7vRyB27AADtH4"]
...
show less
Hacking
Web App Attack
🇨🇦
polycoda
2026-09-13 23:44:22
(4 hours ago)
AutoBlock: ↪️ Excessive 30X Errors (Decay-Based)
Bad Web Bot
🇵🇱
Budyn
2026-09-13 22:52:11
(5 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.website | URI: /index.php/jk | UA: Mozilla/5.0 zgrab/0.x | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-13 22:10:24
(5 hours ago)
[Mon Sep 14 08:10:23.737089 2026] [security2:error] [pid 31523] [client 169.58.140.171:49454] [clien ...
show more
[Mon Sep 14 08:10:23.737089 2026] [security2:error] [pid 31523] [client 169.58.140.171:49454] [client 169.58.140.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "furst.com.au"] [uri "/index.php/jk"] [unique_id "aqcfT24xqUcNIqqgwZSE9gAAAAI"]
...
show less
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-13 22:07:02
(5 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hugopvigo
2026-09-13 20:47:02
(7 hours ago)
"2026-09-13 20:47:02+00:00 169.58.140.171 IP con score alto (100) detectada en el log."
Brute-Force
SSH