π¬π§
cg-design.co.uk
2026-07-23 09:52:23
(1 day ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 194.180.236.55 (US/United States/-)
Brute-Force
π«π·
Jean Valjean
2026-07-22 21:32:31
(1 day ago)
Fail2ban Caboom : wp-login.php Bruteforce
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-22 11:20:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:20:07.617559 2026] [security2:error] [pid 17412:tid 17421] [client 194.180.236.55:27177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catislandrentals.com.nicholsinvest.com"] [uri "/wp-config.php.orig"] [unique_id "ahA751N6lr2zvf5dKYAvVQAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
nyt
2026-05-22 01:33:03
(2 months ago)
WP Config Probe
Web App Attack
πΊπΈ
mnsf
2026-05-21 07:06:35
(2 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-20 20:44:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 16:43:56.614249 2026] [security2:error] [pid 28467:tid 28467] [client 194.180.236.55:61031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geckoturner.chezlubacov.xyz"] [uri "/wp-config.php.old"] [unique_id "ag4dDJYc9YLNmZTQAS74UQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-20 12:40:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:39:58.802344 2026] [security2:error] [pid 3419:tid 3419] [client 194.180.236.55:38593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vintageamptubes.ink2wear.com"] [uri "/.wp-config.php.swp"] [unique_id "ag2rnmIyB9wA9Ti9cPUtkAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hagen Schoebel
2026-05-17 00:13:44
(2 months ago)
Blocked by CrowdSec - crowdsecurity/http-wordpress-scan (US)
Port Scan
Brute-Force
Web App Attack
SSH
πΊπΈ
webgobe
2026-05-11 23:15:48
(2 months ago)
jow-Joomla User : try to access forms...
Hacking
Anonymous
2026-04-20 14:13:44
(3 months ago)
194.180.236.55 - - [20/Apr/2026:14:13:43 +0000] "GET /.env_1 HTTP/1.1" 302 3601 "-" "Mozilla/5.0 (Wi ...
show more
194.180.236.55 - - [20/Apr/2026:14:13:43 +0000] "GET /.env_1 HTTP/1.1" 302 3601 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
mk-dizajn.hr
2026-04-17 02:04:52
(3 months ago)
$f2bV_matches
Bad Web Bot
Anonymous
2026-04-12 18:22:27
(3 months ago)
Forum/form spam
Web Spam
πΊπΈ
TPI-Abuse
2026-03-10 02:08:25
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 22:08:19.176078 2026] [security2:error] [pid 26370:tid 26370] [client 194.180.236.55:52829] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||evolute.io|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "evolute.io"] [uri "/"] [unique_id "aa99E-dCY6Wjsmnz60IIFgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-06 19:13:47
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 194.180.236.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 14:13:40.023775 2026] [security2:error] [pid 8478:tid 8478] [client 194.180.236.55:26517] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||goalsnet.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "goalsnet.net"] [uri "/"] [unique_id "aasnZGbNO5dYHHGljJf0vgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-04 16:16:40
(4 months ago)
Forum/form spam
Web Spam