๐ฉ๐ช
FeG Deutschland
2026-09-28 19:35:43
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐จ๐ฟ
Countryman
2026-09-13 00:10:01
(2 weeks ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐จ๐ฟ
lp
2026-09-12 01:51:02
(2 weeks ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 194.180.232.120
2026-09-12T03:13:32+0 ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 194.180.232.120
2026-09-12T03:13:32+02:00 vpn Access-Reject 'mihai.nae' station: 194.180.232.120 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-12T03:14:53+02:00 vpn Access-Reject 'daniela.konovala' station: 194.180.232.120 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
Countryman
2026-09-12 00:10:01
(2 weeks ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐ฉ๐ช
HandyTreff.de
2026-08-05 11:00:41
(1 month ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -48.569 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -48.569 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.6523.2
show less
Web App Attack
Bad Web Bot
๐ท๐ธ
Smel
2026-06-24 04:52:09
(3 months ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 22:26:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 194.180.232.120 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 194.180.232.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 18:26:36.305637 2026] [security2:error] [pid 31612:tid 31612] [client 194.180.232.120:19117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dvdmasters.com"] [uri "/wp-config.txt"] [unique_id "ag-GnL3qEPYD88aFuge4_gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 19:53:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 194.180.232.120 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 194.180.232.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 15:53:21.069637 2026] [security2:error] [pid 14540:tid 14540] [client 194.180.232.120:59937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radicalchange.org"] [uri "/.wp-config.php.swp"] [unique_id "ag4RMdBpOXaV6Z7AxtloJwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 16:11:36
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 194.180.232.120 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 194.180.232.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:11:31.156138 2026] [security2:error] [pid 17790:tid 17790] [client 194.180.232.120:39643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abundancecompany.com"] [uri "/wp-config.php.old"] [unique_id "ag3dMzDlgNx2NvJ9RPWyGQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 04:02:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 194.180.232.120 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 194.180.232.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 00:02:32.367497 2026] [security2:error] [pid 17432:tid 17432] [client 194.180.232.120:28337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caddydad.com"] [uri "/wp-config.php.old"] [unique_id "ag0yWHQTuL3UEI0q5zAu-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-04 08:13:07
(4 months ago)
194.180.232.120 - - [04/May/2026:16:13:07 +0800] "GET /wp-content/uploads/web.config HTTP/1.1" 301 - ...
show more
194.180.232.120 - - [04/May/2026:16:13:07 +0800] "GET /wp-content/uploads/web.config HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-04-17 10:45:01
(5 months ago)
ModSecurity rule 949110 triggered on dedicated. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
mind5t0rm
2026-02-05 01:04:40
(7 months ago)
(XMLRPC) WP XMLPRC Attack 194.180.232.120 (US/United States/-): 3 in the last 3600 secs; Ports: *; D ...
show more
(XMLRPC) WP XMLPRC Attack 194.180.232.120 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 194.180.232.120 - - [05/Feb/2026:08:04:37 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/8.6.0"
194.180.232.120 - - [05/Feb/2026:08:04:38 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "Wget/1.21.4"
194.180.232.120 - - [05/Feb/2026:08:04:39 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/8.6.0"
show less
Port Scan
๐ฌ๐ง
SilverZippo
2026-02-04 04:43:28
(7 months ago)
Web App Attack
Web App Attack
๐จ๐ญ
backslash
2026-02-03 23:00:06
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot