🇸🇮
administrator
2026-09-04 22:32:54
(5 days ago)
2026-09-03 16:21:39,910 fail2ban.actions [1191]: NOTICE [error-bots] Ban 185.243.218.182
202 ...
show more
2026-09-03 16:21:39,910 fail2ban.actions [1191]: NOTICE [error-bots] Ban 185.243.218.182
2026-09-03 16:21:39,910 fail2ban.actions [1191]: NOTICE [error-bots] Ban 185.243.218.182
2026-09-03 16:21:39,910 fail2ban.actions [1191]: NOTICE [error-bots] Ban 185.243.218.182
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:14
(5 days ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇩🇪
FeG Deutschland
2026-09-04 17:48:26
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇩🇪
John Chrys.
2026-09-04 10:02:21
(5 days ago)
185.243.218.182 - - [04/Sep/2026:13:02:18 +0300] "POST /index.php?option=com_jce&task=profiles.impor ...
show more
185.243.218.182 - - [04/Sep/2026:13:02:18 +0300] "POST /index.php?option=com_jce&task=profiles.import HTTP/1.1" 403 2218 "https://iaveris.gr/index.php?option=com_users" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2824.66 Safari/537.36"
185.243.218.182 - - [04/Sep/2026:13:02:18 +0300] "POST /index.php?option=com_jce&task=profiles.import HTTP/1.1" 403 2218 "https://iaveris.gr/index.php?option=com_users" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2824.66 Safari/537.36"
185.243.218.182 - - [04/Sep/2026:13:02:18 +0300] "POST /index.php?option=com_jce&task=profiles.import HTTP/1.1" 403 2819 "https://iaveris.gr/index.php?option=com_users" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2824.66 Safari/537.36"
185.243.218.182 - - [04/Sep/2026:13:02:19 +0300] "POST /index.php?option=com_jce&task=profiles.import HTTP/1.1" 403 2218 "https://iaveris.gr/index.php?option=com_users" "Mozilla/
...
show less
Brute-Force
Web App Attack
🇧🇾
lns.bz
2026-09-04 08:08:48
(5 days ago)
Too many 404 requests [BY]
Web App Attack
🇳🇱
Savvii
2026-09-04 06:02:05
(5 days ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-04 00:21:15
(6 days ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
pixelXp
2026-09-04 00:20:43
(6 days ago)
Reason:10 (Web Spam), Via: vcluifeltje.nl/index-ajax.php, Message: detectSuspiciousPost count:6 deta ...
show more
Reason:10 (Web Spam), Via: vcluifeltje.nl/index-ajax.php, Message: detectSuspiciousPost count:6 details: Array -
show less
Web Spam
🇺🇸
TPI-Abuse
2026-09-03 22:57:45
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 185.243.218.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.243.218.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:57:38.156385 2026] [security2:error] [pid 29009:tid 29009] [client 185.243.218.182:61820] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.fusteriafontane.com|F|2"] [data ".pkg_sourcerer.sys.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.fusteriafontane.com"] [uri "/language/en-GB/en-GB.pkg_sourcerer.sys.ini"] [unique_id "apn7Yh0oCzJ_bXC_I8QMCAAAABM"], referer: https://www.fusteriafontane.com/administrator/manifests/packages/pkg_sourcerer.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 22:16:32
(6 days ago)
WEB attack
Brute-Force
🇳🇱
Savvii
2026-09-03 20:31:24
(6 days ago)
20 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 19:39:10
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 185.243.218.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.243.218.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:39:06.018156 2026] [security2:error] [pid 2697:tid 2697] [client 185.243.218.182:13562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||encoremtmorris.com|F|2"] [data ".pkg_sourcerer.sys.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "encoremtmorris.com"] [uri "/language/en-GB/en-GB.pkg_sourcerer.sys.ini"] [unique_id "apnM2m1F4-ETG66dT8K_7wAAAAU"], referer: https://encoremtmorris.com/administrator/manifests/packages/pkg_sourcerer.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 18:33:12
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 185.243.218.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.243.218.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:33:06.487484 2026] [security2:error] [pid 1600440:tid 1600464] [client 185.243.218.182:57756] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drronaldhecker.com|F|2"] [data ".pkg_sourcerer.sys.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drronaldhecker.com"] [uri "/language/en-GB/en-GB.pkg_sourcerer.sys.ini"] [unique_id "apm9YqCyJIsNKL9klsEvbAAAAMw"], referer: https://drronaldhecker.com/administrator/manifests/packages/pkg_sourcerer.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Execoop
2026-09-03 18:26:41
(6 days ago)
API LLMjacking (Ollama) (observed): 3 HTTP; attempted cryptomining; Ollama: /v1/chat/completions
Hacking
Web App Attack
🇩🇪
heyzg
2026-09-03 17:13:16
(6 days ago)
API LLMjacking (Ollama) (observed): 3 HTTP; attempted cryptomining; Ollama: /api/generate
Hacking
Web App Attack