๐ฆ๐บ
MAGIC
2026-04-30 00:29:41
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-22 03:32:07
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 191.96.106.23 (host2.wedjhosting.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.106.23 (host2.wedjhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 23:32:01.947947 2026] [security2:error] [pid 2058422:tid 2058422] [client 191.96.106.23:52839] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogerheath.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogerheath.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aehBMb6KsR7Lx6f31y3lPgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 02:26:35
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 191.96.106.23 (host2.wedjhosting.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.106.23 (host2.wedjhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 22:26:27.397018 2026] [security2:error] [pid 1862982:tid 1862982] [client 191.96.106.23:62884] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||advantagept.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "advantagept.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aegx09n-zGFAzGr2_gu2wwAAAAM"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-05 12:12:06
(2 months ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐ซ๐ท
Dampen59
2026-01-28 05:22:32
(4 months ago)
(smtpauth) Failed SMTP AUTH login from 191.96.106.23 (US/United States/host2.wedjhosting.com): 5 in ...
show more
(smtpauth) Failed SMTP AUTH login from 191.96.106.23 (US/United States/host2.wedjhosting.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-01-28 06:21:21 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:34997: 535 Incorrect authentication data ([email protected] )
2026-01-28 06:22:10 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:32279: 535 Incorrect authentication data ([email protected] )
2026-01-28 06:22:16 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:48902: 535 Incorrect authentication data ([email protected] )
2026-01-28 06:22:20 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:9402: 535 Incorrect authentication data ([email protected] )
2026-01-28 06:22:31 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:10275: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
๐ซ๐ท
Dampen59
2026-01-24 23:42:57
(4 months ago)
(smtpauth) Failed SMTP AUTH login from 191.96.106.23 (US/United States/host2.wedjhosting.com): 5 in ...
show more
(smtpauth) Failed SMTP AUTH login from 191.96.106.23 (US/United States/host2.wedjhosting.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-01-24 23:41:47 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:42254: 535 Incorrect authentication data ([email protected] )
2026-01-24 23:42:23 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:55673: 535 Incorrect authentication data ([email protected] )
2026-01-24 23:42:45 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:16145: 535 Incorrect authentication data ([email protected] )
2026-01-24 23:42:51 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:20072: 535 Incorrect authentication data ([email protected] )
2026-01-24 23:42:55 dovecot_login authenticator failed for H=(ADMIN) [191.96.106.23]:14891: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
Anonymous
2025-10-23 17:15:14
(7 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
Anonymous
2025-10-16 16:10:19
(8 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
Anonymous
2025-10-15 16:31:09
(8 months ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
๐ฑ๐ป
garmtech.com
2025-09-22 15:56:57
(8 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 18-56.191.96.106.23.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 18-56.191.96.106.23.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ณ๐ฑ
exxos
2025-09-21 11:05:36
(8 months ago)
Attacks with Bad user agents
Hacking
๐บ๐ธ
Xarcotic
2025-08-30 20:02:28
(9 months ago)
SSH login on honeypot.
Brute-Force
SSH
๐ต๐ฑ
sefinek.net
2025-08-30 10:33:33
(9 months ago)
Honeypot hit: Unauthorized traffic (32 bytes of payload); 9944 [11], 6036 [11], 51007 [11], 19071 [1 ...
show more
Honeypot hit: Unauthorized traffic (32 bytes of payload); 9944 [11], 6036 [11], 51007 [11], 19071 [11], 45001 [11], 21242 [8] TCP
show less
Port Scan
๐ฉ๐ช
stinpriza
2025-08-23 10:52:20
(9 months ago)
Web App Attack
Web App Attack
๐ฎ๐ช
tines_bot
2025-04-10 12:00:14
(1 year ago)
This IP is associated with RDP abuse. It was found in a paste by https://twitter.com/RdpSnitch - htt ...
show more
This IP is associated with RDP abuse. It was found in a paste by https://twitter.com/RdpSnitch - https://pastebin.com/Ui7WpWGu
For more information, or to report interesting/incorrect findings, contact us - [email protected]
show less
Brute-Force