๐บ๐ฆ
URAN Publishing Service
2026-02-07 13:22:31
(3 months ago)
185.194.178.76 - - [07/Feb/2026:15:22:31 +0200] "GET //wp-content/plugins/about.php HTTP/1.1" 404 28 ...
show more
185.194.178.76 - - [07/Feb/2026:15:22:31 +0200] "GET //wp-content/plugins/about.php HTTP/1.1" 404 286 "-" "Go-http-client/1.1"
185.194.178.76 - - [07/Feb/2026:15:22:31 +0200] "GET //wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 404 286 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐ฉ๐ช
LRob.fr
2026-02-07 00:52:10
(3 months ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ซ๐ท
tilellit.pro
2026-01-30 23:47:11
(4 months ago)
Fail2Ban banned 185.194.178.76 for security violations in jail wp-armour. Log: 2026/01/30 23:47:11 [ ...
show more
Fail2Ban banned 185.194.178.76 for security violations in jail wp-armour. Log: 2026/01/30 23:47:11 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 185.194.178.76 | Target: wplogin" , client: 185.194.178.76, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED]
...
show less
Web Spam
๐ซ๐ท
tilellit.pro
2026-01-30 04:53:08
(4 months ago)
Fail2Ban banned 185.194.178.76 for security violations in jail wp-armour. Log: 2026/01/30 04:53:08 [ ...
show more
Fail2Ban banned 185.194.178.76 for security violations in jail wp-armour. Log: 2026/01/30 04:53:08 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 185.194.178.76 | Target: wplogin" , client: 185.194.178.76, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED]
...
show less
Web Spam
๐ฉ๐ช
juutis
2026-01-30 04:39:05
(4 months ago)
185.194.178.76 - - [30/Jan/2026:03:34:40 +0100] "POST /wp-login.php HTTP/1.0" 200 15326 "-" "Mozilla ...
show more
185.194.178.76 - - [30/Jan/2026:03:34:40 +0100] "POST /wp-login.php HTTP/1.0" 200 15326 "-" "Mozilla/5.0"
185.194.178.76 - - [30/Jan/2026:04:10:43 +0100] "POST /wp-login.php HTTP/1.0" 200 15326 "-" "Mozilla/5.0"
185.194.178.76 - - [30/Jan/2026:05:39:03 +0100] "POST /wp-login.php HTTP/1.0" 200 15326 "-" "Mozilla/5.0"
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-01-28 08:06:21
(4 months ago)
Try to access /vendor/phpunit/phpunit/phpunit.xsd
Web App Attack
๐บ๐ธ
dtorrer
2026-01-27 22:23:19
(4 months ago)
General vulnerability scan.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-27 16:23:03
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 27 11:22:57.937524 2026] [security2:error] [pid 26042:tid 26042] [client 185.194.178.76:49145] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alphazeta.net|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alphazeta.net"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aXjmYe0SrefgvfIxR0evbQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-27 15:25:44
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 27 10:25:37.195597 2026] [security2:error] [pid 22644:tid 22644] [client 185.194.178.76:48345] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stardancertantra.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stardancertantra.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aXjY8WOmbUrTJ9FR46jxHgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-27 06:50:32
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 27 01:50:28.132170 2026] [security2:error] [pid 22509:tid 22509] [client 185.194.178.76:56053] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||compliancedepts.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "compliancedepts.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aXhgNPf0LtyZMMU9RtdTyQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-27 04:31:53
(4 months ago)
Blocking for trying to access an exploit file: //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-27 03:04:31
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 22:04:26.645369 2026] [security2:error] [pid 3366310:tid 3366310] [client 185.194.178.76:31647] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||automatebi.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "automatebi.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aXgrOjii-EdIWQ6ubpG9LAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-27 02:42:52
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 21:42:47.901890 2026] [security2:error] [pid 12270:tid 12270] [client 185.194.178.76:65091] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stkm.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stkm.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aXgmJ1E0bEmB35I8EjBJ8QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-27 01:40:32
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 20:40:29.885925 2026] [security2:error] [pid 16538:tid 16538] [client 185.194.178.76:34741] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fingershrine.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fingershrine.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aXgXjcFOptgEkUWGN6V-NAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-19 23:38:11
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.194.178.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 18:38:07.038436 2026] [security2:error] [pid 26916:tid 26916] [client 185.194.178.76:39581] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fitnessdoctors.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fitnessdoctors.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aW7AXxNZvwF7x2GhaVX7LgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack