π©πͺ
brechtr
2026-09-14 19:34:10
(8 hours ago)
[Press84-BanHammer] bad username β Sourced from: press84.com β Request: POST /wp-login.php
Brute-Force
π§πͺ
madeit
2026-09-11 04:09:58
(3 days ago)
Web App Attack
πͺπΈ
el-brujo
2026-09-07 15:36:41
(1 week ago)
07/Sep/2026:17:36:41.565639 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
07/Sep/2026:17:36:41.565639 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.141.184] ModSecurity: Warning. Pattern match "[\\\\\\\\n\\\\\\\\r]" at ARGS_NAMES:\\\\r\\\\n<methodCall>\\\\r\\\\n<methodName>system.listMethods</methodName>\\\\r\\\\n<params></params>\\\\r\\\\n</methodCall>\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "172"] [id "921150"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)"] [data "Matched Data: \\\\x0d found within ARGS_NAMES:\\\\x5cr\\\\x5cn<methodCall>\\\\x5cr\\\\x5cn<methodName>system.listMethods</methodName>\\\\x5cr\\\\x5cn<params></params>\\\\x5cr\\\\x5cn</methodCall>\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn: \\\\x0d\\\\x0a<methodCall>\\\\x0d\\\\x0a<methodName>system.listMethods</methodName>\\\\x0d\\\\x0a<params></params>\\\\x0d\\\\x0a</methodCall>\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a"]
...
show less
Hacking
Web App Attack
πͺπΈ
el-brujo
2026-08-28 10:24:11
(2 weeks ago)
28/Aug/2026:12:24:11.041145 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Aug/2026:12:24:11.041145 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.141.184] ModSecurity: Warning. Pattern match "[\\\\\\\\n\\\\\\\\r]" at ARGS_NAMES:\\\\r\\\\n<methodCall>\\\\r\\\\n<methodName>system.listMethods</methodName>\\\\r\\\\n<params></params>\\\\r\\\\n</methodCall>\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "172"] [id "921150"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)"] [data "Matched Data: \\\\x0d found within ARGS_NAMES:\\\\x5cr\\\\x5cn<methodCall>\\\\x5cr\\\\x5cn<methodName>system.listMethods</methodName>\\\\x5cr\\\\x5cn<params></params>\\\\x5cr\\\\x5cn</methodCall>\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn: \\\\x0d\\\\x0a<methodCall>\\\\x0d\\\\x0a<methodName>system.listMethods</methodName>\\\\x0d\\\\x0a<params></params>\\\\x0d\\\\x0a</methodCall>\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a"]
...
show less
Hacking
Web App Attack
πͺπΈ
el-brujo
2026-08-24 23:00:56
(3 weeks ago)
25/Aug/2026:01:00:55.623909 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
25/Aug/2026:01:00:55.623909 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.141.184] ModSecurity: Warning. Pattern match "[\\\\\\\\n\\\\\\\\r]" at ARGS_NAMES:\\\\r\\\\n<methodCall>\\\\r\\\\n<methodName>system.listMethods</methodName>\\\\r\\\\n<params></params>\\\\r\\\\n</methodCall>\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "172"] [id "921150"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)"] [data "Matched Data: \\\\x0d found within ARGS_NAMES:\\\\x5cr\\\\x5cn<methodCall>\\\\x5cr\\\\x5cn<methodName>system.listMethods</methodName>\\\\x5cr\\\\x5cn<params></params>\\\\x5cr\\\\x5cn</methodCall>\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn: \\\\x0d\\\\x0a<methodCall>\\\\x0d\\\\x0a<methodName>system.listMethods</methodName>\\\\x0d\\\\x0a<params></params>\\\\x0d\\\\x0a</methodCall>\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a"]
...
show less
Hacking
Web App Attack
πͺπΈ
el-brujo
2026-08-23 17:40:49
(3 weeks ago)
23/Aug/2026:19:40:49.389219 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
23/Aug/2026:19:40:49.389219 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.141.184] ModSecurity: Warning. Pattern match "[\\\\\\\\n\\\\\\\\r]" at ARGS_NAMES:\\\\r\\\\n<methodCall>\\\\r\\\\n<methodName>system.listMethods</methodName>\\\\r\\\\n<params></params>\\\\r\\\\n</methodCall>\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "172"] [id "921150"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)"] [data "Matched Data: \\\\x0d found within ARGS_NAMES:\\\\x5cr\\\\x5cn<methodCall>\\\\x5cr\\\\x5cn<methodName>system.listMethods</methodName>\\\\x5cr\\\\x5cn<params></params>\\\\x5cr\\\\x5cn</methodCall>\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn: \\\\x0d\\\\x0a<methodCall>\\\\x0d\\\\x0a<methodName>system.listMethods</methodName>\\\\x0d\\\\x0a<params></params>\\\\x0d\\\\x0a</methodCall>\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a"]
...
show less
Hacking
Web App Attack
π§π¬
Stoyko Stoykov
2026-08-23 03:00:17
(3 weeks ago)
172.71.141.184 - - [23/Aug/2026:06:00:16 +0300] "GET /simple.php HTTP/1.1" 301 162 "-" "-"
...
Hacking
Web App Attack
π©πͺ
abdubhai
2026-08-20 11:03:30
(3 weeks ago)
172.71.141.184 - - [20/Aug/2026:
...
Brute-Force
πͺπΈ
el-brujo
2026-08-20 00:41:48
(3 weeks ago)
20/Aug/2026:02:41:48.318175 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
20/Aug/2026:02:41:48.318175 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.141.184] ModSecurity: Warning. Pattern match "[\\\\\\\\n\\\\\\\\r]" at ARGS_NAMES:\\\\r\\\\n<methodCall>\\\\r\\\\n<methodName>system.listMethods</methodName>\\\\r\\\\n<params></params>\\\\r\\\\n</methodCall>\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n\\\\r\\\\n. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "172"] [id "921150"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)"] [data "Matched Data: \\\\x0d found within ARGS_NAMES:\\\\x5cr\\\\x5cn<methodCall>\\\\x5cr\\\\x5cn<methodName>system.listMethods</methodName>\\\\x5cr\\\\x5cn<params></params>\\\\x5cr\\\\x5cn</methodCall>\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn\\\\x5cr\\\\x5cn: \\\\x0d\\\\x0a<methodCall>\\\\x0d\\\\x0a<methodName>system.listMethods</methodName>\\\\x0d\\\\x0a<params></params>\\\\x0d\\\\x0a</methodCall>\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a\\\\x0d\\\\x0a"]
...
show less
Hacking
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-19 21:25:35
(3 weeks ago)
[20/Aug/2026:00:25:34 +0300] -- 172.71.141.184 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[20/Aug/2026:00:25:34 +0300] -- 172.71.141.184 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
mawan
2026-08-19 09:47:20
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
mawan
2026-08-16 21:50:23
(4 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π§π¬
Stoyko Stoykov
2026-08-15 04:05:58
(4 weeks ago)
172.71.141.184 - - [15/Aug/2026:07:05:57 +0300] "GET /x.php HTTP/1.1" 301 162 "-" "-"
...
Hacking
Web App Attack
πΊπΈ
mawan
2026-08-14 16:36:55
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π§π¬
Stoyko Stoykov
2026-08-11 22:47:50
(1 month ago)
172.71.141.184 - - [12/Aug/2026:01:47:50 +0300] "GET /wp-content/admin.php HTTP/1.1" 301 162 "-" "-" ...
show more
172.71.141.184 - - [12/Aug/2026:01:47:50 +0300] "GET /wp-content/admin.php HTTP/1.1" 301 162 "-" "-"
...
show less
Hacking
Web App Attack