๐ฌ๐ง
sc user
2026-09-16 23:33:29
(18 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฌ๐ท
setupgr
2026-09-16 13:18:29
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 194.163.161.67 (FR/France/Bas-Rhin/Lauterbour ...
show more
(mod_security) mod_security (id:11000011) triggered by 194.163.161.67 (FR/France/Bas-Rhin/Lauterbourg/-/[AS51167 Contabo GmbH]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Sep 16 16:18:25.065836 2026] [security2:error] [pid 1196594:tid 1196731] [client 194.163.161.67:61030] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "contaboserver.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: vmi3574613.contaboserver.net"] [severity "CRITICAL"] [hostname "ions.gr"] [uri "/wp-admin/css/"] [unique_id "aqqXIfgbSDJUOr7f1bZ02wAABM8"]
show less
Port Scan
๐ช๐ธ
robotstxt
2026-09-16 12:14:57
(1 day ago)
194.163.161.67 - - [16/Sep/2026:12:14:19 +0000] "GET /wp-includes/ HTTP/2.0" 403 21343 "-" "Mozilla/ ...
show more
194.163.161.67 - - [16/Sep/2026:12:14:19 +0000] "GET /wp-includes/ HTTP/2.0" 403 21343 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "194.163.161.67" edge="172.68.110.85"
194.163.161.67 - - [16/Sep/2026:12:14:45 +0000] "GET /wp-includes/css/dist/ HTTP/2.0" 403 21342 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "194.163.161.67" edge="172.68.110.85"
194.163.161.67 - - [16/Sep/2026:12:14:48 +0000] "GET /wp-includes/fonts/ HTTP/2.0" 403 21411 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "194.163.161.67" edge="172.68.110.85"
194.163.161.67 - - [16/Sep/2026:12:14:49 +0000] "GET /wp-includes/ID3/ HTTP/2.0" 403 21343 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "194.163.161.67" edge="172.68.110.85"
194.163.1
...
show less
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-16 11:50:04
(1 day ago)
194.163.161.67 - - [16/Sep/2026:12:50:01 +0100] "GET /cgi-bin/ HTTP/2.0" 404 994 "-" "Mozilla/5.0 (W ...
show more
194.163.161.67 - - [16/Sep/2026:12:50:01 +0100] "GET /cgi-bin/ HTTP/2.0" 404 994 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-09-16 08:20:29
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-09-16 07:59:13
(1 day ago)
Repeated requests for suspicious nonexistent URLs, for example: /wp-admin/maint/ (HTTP/1.1 port 443, ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /wp-admin/maint/ (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36")
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-16 07:57:18
(1 day ago)
194.163.161.67 - - [16/Sep/2026:07:54:37 +0000] "GET /wp-includes/sitemaps/ HTTP/2.0" 403 33532 "-" ...
show more
194.163.161.67 - - [16/Sep/2026:07:54:37 +0000] "GET /wp-includes/sitemaps/ HTTP/2.0" 403 33532 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "194.163.161.67"
194.163.161.67 - - [16/Sep/2026:07:55:31 +0000] "GET /wp-includes/js/ HTTP/2.0" 403 33531 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "194.163.161.67"
194.163.161.67 - - [16/Sep/2026:07:55:47 +0000] "GET /wp-includes/js/plupload/ HTTP/2.0" 403 33534 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "194.163.161.67"
194.163.161.67 - - [16/Sep/2026:07:55:58 +0000] "GET /wp-includes/widgets/ HTTP/2.0" 403 33511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "194.163.161.67"
194.163.161.67 - - [16/Sep/2026:07:56:52 +0000] "GET /.well-known/ HTTP/2.0" 403
...
show less
Web App Attack
Anonymous
2026-09-16 07:47:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /admin/ HTTP/1.1, GET /cgi-bin/ HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-09-16 05:48:25
(1 day ago)
194.163.161.67 - - [16/Sep/2026:13:48:24 +0800] "GET /cgi-bin/ HTTP/1.1" 301 245 "-" "Mozilla/5.0 (W ...
show more
194.163.161.67 - - [16/Sep/2026:13:48:24 +0800] "GET /cgi-bin/ HTTP/1.1" 301 245 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
sc user
2026-09-15 22:24:11
(1 day ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐จ๐ญ
4server
2026-09-15 18:26:17
(1 day ago)
''
Hacking
Web App Attack
๐บ๐ธ
dot.mg
2026-09-15 17:00:25
(2 days ago)
Bad behaviour
Web Spam
๐ฉ๐ช
bazter.pro
2026-09-15 15:47:57
(2 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-15 15:40:44
(2 days ago)
Web attack/malicious scanning detected
Web App Attack