π«π·
Safronus
2026-10-05 21:07:22
(2 days ago)
Banned by fail2ban jail=nginx-noscript match=$f2bV_matches
Bad Web Bot
Web App Attack
π«π·
Entalpi.net
2026-10-05 17:20:57
(2 days ago)
Repeated requests against sensitive web endpoints
Web App Attack
Anonymous
2026-09-16 21:35:55
(3 weeks ago)
[redacted] 181.215.65.7 - - [16/Sep/2026:23:35:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mo ...
show more
[redacted] 181.215.65.7 - - [16/Sep/2026:23:35:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
[redacted] 181.215.65.7 - - [16/Sep/2026:23:35:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/120.0.2210.91"
[redacted] 181.215.65.7 - - [16/Sep/2026:23:35:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Linux; Android 14; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36"
[redacted] 181.215.65.7 - - [16/Sep/2026:23:35:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Linux; Android 14; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36"
[redacted] 181.215.65.7 - - [16/Sep/2026:23:35:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_2_1)
...
show less
Hacking
Web App Attack
π³π±
homeshowdomain.nl
2026-08-10 21:59:52
(1 month ago)
Auto-ban: >3000 req/min op 2026-08-10
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-09 22:54:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 18:54:21.023063 2026] [security2:error] [pid 20035:tid 20049] [client 181.215.65.7:52615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.14"] [uri "/conf/.env"] [unique_id "ankFHXSrIjVrX_GEVDFGeQAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
neron
2026-08-09 00:29:21
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΊπΈ
xmission.com
2026-08-04 19:56:13
(2 months ago)
Blocked by UFW (TCP on 60973)
Source port: 50123
TTL: 53
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 60973)
Source port: 50123
TTL: 53
Packet length: 60
TOS: 0x08
This report (for 181.215.65.7) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-07-27 19:05:37
(2 months ago)
Try to connect to Port_Scan_6379_stealth
Port Scan
π©πͺ
club77
2026-07-18 05:17:29
(2 months ago)
181.215.65.7 - - [18/Jul/2026:13:17:25 +0800] "GET /3PJcpMFsD8B.php HTTP/2.0" 404 101692 "http://vic ...
show more
181.215.65.7 - - [18/Jul/2026:13:17:25 +0800] "GET /3PJcpMFsD8B.php HTTP/2.0" 404 101692 "http://vicinity.life/3PJcpMFsD8B.php" "Go-http-client/2.0"
181.215.65.7 - - [18/Jul/2026:13:17:27 +0800] "GET /5PJcpMFsD8B.php HTTP/2.0" 404 101331 "http://vicinity.life/5PJcpMFsD8B.php" "Go-http-client/2.0"
181.215.65.7 - - [18/Jul/2026:13:17:28 +0800] "GET /dropdown.php HTTP/2.0" 404 101313 "http://vicinity.life/dropdown.php" "Go-http-client/2.0"
...
show less
Web App Attack
πΊπ¦
URAN Publishing Service
2026-07-18 04:47:00
(2 months ago)
Bad Web Bot
DDoS Attack
Bad Web Bot
πΊπΈ
Lee Daniel
2026-07-18 03:42:38
(2 months ago)
181.215.65.7 - - [17/Jul/2026:23:42:34 -0400] "GET /templates/cassiopeia/error.php HTTP/1.1" 404 202 ...
show more
181.215.65.7 - - [17/Jul/2026:23:42:34 -0400] "GET /templates/cassiopeia/error.php HTTP/1.1" 404 20282 "http://harrymanning.com/templates/cassiopeia/error.php" "Go-http-client/2.0"
181.215.65.7 - - [17/Jul/2026:23:42:35 -0400] "GET /templates/ja_purity/index.php HTTP/1.1" 404 20282 "http://harrymanning.com/templates/ja_purity/index.php" "Go-http-client/2.0"
181.215.65.7 - - [17/Jul/2026:23:42:36 -0400] "GET /templates/protostar/error.php HTTP/1.1" 404 20281 "http://harrymanning.com/templates/protostar/error.php" "Go-http-client/2.0"
181.215.65.7 - - [17/Jul/2026:23:42:36 -0400] "GET /templates/beez3/jsstrings.php HTTP/1.1" 404 144752 "http://harrymanning.com/templates/beez3/jsstrings.php" "Go-http-client/2.0"
181.215.65.7 - - [17/Jul/2026:23:42:37 -0400] "GET /templates/atomic/index.php HTTP/1.1" 404 144749 "http://harrymanning.com/templates/atomic/index.php" "Go-http-client/2.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-07-18 03:21:00
(2 months ago)
181.215.65.7 - - [18/Jul/2026:06:19:58 +0300] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 404 ...
show more
181.215.65.7 - - [18/Jul/2026:06:19:58 +0300] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 404 251 "-" "Go-http-client/1.1"
181.215.65.7 - - [18/Jul/2026:06:20:58 +0300] "GET /wp-includes/ID3/index.php HTTP/1.1" 404 251 "-" "Go-http-client/1.1"
...
show less
Web App Attack
πΊπΈ
nyt
2026-07-09 04:04:03
(2 months ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
π«π·
Kenshin869
2026-06-24 00:28:04
(3 months ago)
Wordpress unauthorized access attempt
Brute-Force
π²πΎ
Rizzy
2026-06-23 23:09:35
(3 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack