๐ณ๐ฑ
ConsulHosting
2026-06-21 03:35:49
(10 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 02:45:36
(11 hours ago)
(mod_security) mod_security (id:210580) triggered by 191.96.227.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210580) triggered by 191.96.227.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 22:45:28.577841 2026] [security2:error] [pid 20352:tid 20352] [client 191.96.227.100:61542] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:log_filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||wcsystems.net|F|2"] [data "Matched Data: etc/passwd found within ARGS:log_filename: ../../../../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "wcsystems.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajdQSCrWmWCajmVaT37ljgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-20 23:51:45
(13 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 23:07:19
(14 hours ago)
(mod_security) mod_security (id:210580) triggered by 191.96.227.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210580) triggered by 191.96.227.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 19:07:13.436869 2026] [security2:error] [pid 14074:tid 14074] [client 191.96.227.100:39964] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:log_filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||walkerweb.net|F|2"] [data "Matched Data: etc/passwd found within ARGS:log_filename: ../../../../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "walkerweb.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ajcdIRmYvMehpMHBz9i8mAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 21:29:18
(16 hours ago)
191.96.227.100 detected on srv01
Brute-Force
๐ณ๐ด
jad-abuse
2026-06-20 16:29:43
(21 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin, ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin, path_traversal. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-20 13:31:58
(1 day ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 191.96.227.100 (US/United States/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 191.96.227.100 (US/United States/-): 1 in the last 3600 secs (0-196)
show less
Hacking
Anonymous
2026-02-18 14:31:02
(4 months ago)
...
Brute-Force
๐บ๐ธ
jfz-abuse
2026-02-18 14:12:32
(4 months ago)
fail2ban: postfix-sasl
...
Brute-Force
Anonymous
2026-02-18 13:59:19
(4 months ago)
2026-02-18T14:59:03.182199+01:00 zelda postfix/submission/smtpd[3160531]: warning: unknown[191.96.22 ...
show more
2026-02-18T14:59:03.182199+01:00 zelda postfix/submission/smtpd[3160531]: warning: unknown[191.96.227.100]: SASL PLAIN authentication failed: (reason unavailable), [email protected]
2026-02-18T14:59:09.498791+01:00 zelda postfix/submission/smtpd[3160531]: warning: unknown[191.96.227.100]: SASL LOGIN authentication failed: (reason unavailable), [email protected]
2026-02-18T14:59:16.311792+01:00 zelda postfix/smtps/smtpd[3158485]: warning: unknown[191.96.227.100]: SASL PLAIN authentication failed: (reason unavailable), [email protected]
show less
Brute-Force
๐จ๐ฆ
Mediashaker
2026-02-18 13:57:36
(4 months ago)
(smtpauth) Failed SMTP AUTH login from 191.96.227.100 (US/United States/-)
Brute-Force
๐บ๐ธ
bigscoots.com
2026-02-18 12:58:46
(4 months ago)
(smtpauth) Failed SMTP AUTH login from 191.96.227.100 (US/United States/-): 5 in the last 3600 secs; ...
show more
(smtpauth) Failed SMTP AUTH login from 191.96.227.100 (US/United States/-): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2026-02-18 07:57:18 dovecot_plain authenticator failed for H=([10.41.18.247]) [191.96.227.100]:43465: 535 Incorrect authentication data ([email protected] )
2026-02-18 07:57:24 dovecot_login authenticator failed for H=([10.41.18.247]) [191.96.227.100]:43465: 535 Incorrect authentication data ([email protected] )
2026-02-18 07:57:30 dovecot_plain authenticator failed for H=([10.41.18.247]) [191.96.227.100]:61445: 535 Incorrect authentication data ([email protected] )
2026-02-18 07:57:36 dovecot_login authenticator failed for H=([10.41.18.247]) [191.96.227.100]:61445: 535 Incorrect authentication data ([email protected] )
2026-02-18 07:58:45 dovecot_plain authenticator failed for H=([10.41.18.247]) [191.96.227.100]:26233: 535 Incorrect authentication data ([email protected] )
show less
Brute-Force
SSH
๐ฆ๐บ
screwlooseit.com.au
2026-02-18 12:52:39
(4 months ago)
Blocked by CSF 13 firewall - Rule: mysaslmatch
US/United States/-
Web App Attack
๐ฆ๐น
Markus Woegerbauer
2026-02-18 10:36:24
(4 months ago)
(smtpauth) Failed SMTP AUTH login from 191.96.227.100 (US/United States/-)
Brute-Force
๐ฉ๐ช
Nerdscave Hosting
2026-02-18 10:30:59
(4 months ago)
SMTP brute-force detected by Fail2Ban in plesk-postfix jail
Email Spam
Brute-Force