🇨🇭
backslash
2026-09-06 16:06:02
(22 hours ago)
block ruleset 7B8FD6B12C4E12B6F0DAE02E53C0597FBEDDF5BC
Bad Web Bot
🇺🇦
URAN Publishing Service
2026-09-06 15:57:32
(22 hours ago)
[06/Sep/2026:18:57:32 +0300] -- 181.215.65.98 Ban reason: Scanner [CMS_GENERIC] | Request: POST /wp- ...
show more
[06/Sep/2026:18:57:32 +0300] -- 181.215.65.98 Ban reason: Scanner [CMS_GENERIC] | Request: POST /wp-admin/admin-ajax.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
[email protected]
2026-09-02 05:00:07
(5 days ago)
FreePBX [auth_failure] detected in security log. Reported by M C Boyd Services MSP.
Brute-Force
Web App Attack
🇹🇷
neron
2026-08-15 23:06:48
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇺🇸
Jason Howell
2026-08-14 15:24:24
(3 weeks ago)
181.215.65.98 - - [14/Aug/2026:09:59:08 -0500] "POST /wp-login.php HTTP/1.1" 503 19450 "http://cpcal ...
show more
181.215.65.98 - - [14/Aug/2026:09:59:08 -0500] "POST /wp-login.php HTTP/1.1" 503 19450 "http://cpcalendars.gannonpool.com/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/91.0.864.59"
181.215.65.98 - - [14/Aug/2026:10:00:50 -0500] "POST /wp-login.php HTTP/1.1" 503 18378 "http://cpcalendars.gannonpool.com/wp-admin/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36"
181.215.65.98 - - [14/Aug/2026:10:06:31 -0500] "POST /wp-login.php HTTP/1.1" 503 18378 "http://cpcalendars.gannonpool.com/wp-admin/" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_6 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0 Mobile/15E148 Safari/604.1"
181.215.65.98 - - [14/Aug/2026:10:24:17 -0500] "POST /wp-login.php HTTP/1.1" 503 19450 "http://cpcalendars.gannonpool.com/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
181.
...
show less
Web App Attack
🇧🇪
cmbplf
2026-07-30 03:28:44
(1 month ago)
5.008 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
🇺🇸
ambor
2026-06-18 20:06:37
(2 months ago)
L0ss Honeypot: Environment file access attempt. Path: /.env
Web App Attack
🇩🇪
gadix
2026-06-18 13:25:52
(2 months ago)
[18/Jun/2026:15:25:52.035873 +0200] ajPx4Oyl7sa1O_hOwvHQbQAAAA8 181.215.65.98 42638 127.0.0.1 7081
[ ...
show more
[18/Jun/2026:15:25:52.035873 +0200] ajPx4Oyl7sa1O_hOwvHQbQAAAA8 181.215.65.98 42638 127.0.0.1 7081
[18/Jun/2026:15:25:52.210317 +0200] ajPx4Oyl7sa1O_hOwvHQbgAAABQ 181.215.65.98 42648 127.0.0.1 7081
[18/Jun/2026:15:25:52.350489 +0200] ajPx4Oyl7sa1O_hOwvHQbwAAABg 181.215.65.98 42662 127.0.0.1 7081
...
show less
Web App Attack
🇸🇰
GOVCERT
2026-06-17 18:30:37
(2 months ago)
Brute Force Detected
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-06-17 01:17:50
(2 months ago)
15 attempts against mh-modsecurity-ban on pf221103
Brute-Force
Web App Attack
🇫🇷
Kenshin869
2026-05-24 14:53:31
(3 months ago)
Wordpress unauthorized access attempt
Brute-Force
🇺🇸
nyt
2026-05-23 04:38:17
(3 months ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-04-27 02:58:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 22:58:55.564475 2026] [security2:error] [pid 15518:tid 15561] [client 181.215.65.98:22383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unitedonegroup.com"] [uri "/.env.live"] [unique_id "ae7Q7_zgKx07ZJcMiU19BAAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇹
Information Security
2026-04-27 02:40:51
(4 months ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-04-27 02:38:21
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 22:38:02.471245 2026] [security2:error] [pid 31921:tid 31921] [client 181.215.65.98:51067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southtncardio.com"] [uri "/.env.php"] [unique_id "ae7MCmL3TZ1xwJFyHT1plgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack