๐ฌ๐ง
thetomtaylor.co.uk
2026-09-01 13:07:02
(1 hour ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐ธ๐ช
SkyDancer
2026-09-01 06:41:05
(7 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ฉ๐ฐ
HostingGroup
2026-09-01 01:51:53
(12 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 1. First blocked: 2026-09-01.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-09-01 00:22:20
(14 hours ago)
188.166.124.248 - - [01/Sep/2026:08:22:08 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 91824 "-" "Mo ...
show more
188.166.124.248 - - [01/Sep/2026:08:22:08 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 91824 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.166.124.248 - - [01/Sep/2026:08:22:09 +0800] "GET /wp-config.php~ HTTP/1.1" 404 91824 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.166.124.248 - - [01/Sep/2026:08:22:11 +0800] "GET /wp-config.php.save HTTP/1.1" 404 91824 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.166.124.248 - - [01/Sep/2026:08:22:14 +0800] "GET /wp-config.php.old HTTP/1.1" 404 91824 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
188.166.124.248 - - [01/Sep/2026:08:22:15 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 91824 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3
...
show less
Brute-Force
Anonymous
2026-08-31 23:13:33
(15 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-31 13:45:01
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-31 11:27:51
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-31 10:55:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 188.166.124.248 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 188.166.124.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 06:55:45.932392 2026] [security2:error] [pid 17353:tid 17353] [client 188.166.124.248:49014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelmoorefield.com"] [uri "/wp-config.php.bak"] [unique_id "apVdschHs-5_s8vrOxTFRAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 00:40:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 188.166.124.248 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 188.166.124.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 20:40:20.387786 2026] [security2:error] [pid 26359:tid 26359] [client 188.166.124.248:34264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hydrometal-js.com"] [uri "/.git/index"] [unique_id "apTNdE1E4easVDn8ifEqfgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-30 21:55:12
(1 day ago)
csagent: score 20.4: wp-config backup grab x2, 404 noise floor x2; 1 domain(s) in 1s
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-30 12:30:36
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 248_10
Exploited Host
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-30 11:46:47
(2 days ago)
Banned by Fail2Ban
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-30 11:10:01
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
Security_Whaller
2026-08-28 23:58:02
(3 days ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-28 01:02:19
(4 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 1s
Web App Attack