๐ง๐ท
Peregrine
2026-08-29 03:10:09
(2 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 181.215.65.92 172.70.126.34 - - [27/Aug/2026:03:45:32 -03 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 181.215.65.92 172.70.126.34 - - [27/Aug/2026:03:45:32 -0300] "GET /wp-login.php HTTP/1.1" 404 414
show less
Bad Web Bot
๐ง๐ท
Peregrine
2026-08-27 06:45:44
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 181.215.65.92 172.70.126.34 - - [27/Aug/2026:03:45:32 -03 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 181.215.65.92 172.70.126.34 - - [27/Aug/2026:03:45:32 -0300] "GET /wp-login.php HTTP/1.1" 404 414
show less
Bad Web Bot
๐ฉ๐ช
Melle
2026-07-02 09:03:53
(1 month ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 181.215.65.92 triggered 12 events | Det ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 181.215.65.92 triggered 12 events | Detected: 2026-07-02T09:03:37.656226944Z
show less
Web App Attack
Hacking
๐ฆ๐บ
MAGIC
2026-04-25 00:28:39
(4 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฆ๐บ
screwlooseit.com.au
2026-04-07 02:05:25
(4 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
US/United States/-
Web App Attack
๐บ๐ธ
ChamberofCommerce.com
2026-03-09 17:49:26
(5 months ago)
Review System Spam
Web Spam
Blog Spam
๐ฉ๐ช
Lino Project
2026-02-10 02:43:09
(6 months ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/CVE-2017-9841
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-02-03 22:59:29
(6 months ago)
Auto-ban: >3000 req/min op 2026-02-03
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-03 11:20:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 06:20:14.442707 2026] [security2:error] [pid 28140:tid 28140] [client 181.215.65.92:26561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.215"] [uri "/laravel/.env"] [unique_id "aYHZ7s_1Nfuu21MimuLzUQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-03 08:37:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 03:37:29.386754 2026] [security2:error] [pid 1617731:tid 1617838] [client 181.215.65.92:28067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.135"] [uri "/.env"] [unique_id "aYGzyVbW7tBPPxXr8lXhRwAAAcA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-03 06:48:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 01:48:15.594642 2026] [security2:error] [pid 27484:tid 27484] [client 181.215.65.92:20023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.12"] [uri "/.env"] [unique_id "aYGaL76u3U3nxAJ2_WnzUgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Starburst SysOp Team
2026-02-03 01:56:38
(6 months ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-vie6-1)
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-02 20:27:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 02 15:27:52.512457 2026] [security2:error] [pid 25231:tid 25231] [client 181.215.65.92:23827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.136"] [uri "/wp-content/.env"] [unique_id "aYEIyHZzODUhJmM_d9lqVAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-02 16:14:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 02 11:14:10.970586 2026] [security2:error] [pid 15381:tid 15406] [client 181.215.65.92:52619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.178"] [uri "/wp-admin/.env"] [unique_id "aYDNUlFgI12qNuo16feScwAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-02 13:07:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 02 08:07:09.353735 2026] [security2:error] [pid 2209:tid 2209] [client 181.215.65.92:64089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.218"] [uri "/app/config/.env"] [unique_id "aYChfamEk8YKtmDaRgYudgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack