🇩🇪
webanyone
2026-09-20 10:17:52
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇳🇱
javierin
2026-09-19 19:08:17
(1 day ago)
194.195.91.7 - qr.javierin.com - - [19/Sep/2026:19:06:57 +0000] "GET /sleepwalker-como-funciona-la-p ...
show more
194.195.91.7 - qr.javierin.com - - [19/Sep/2026:19:06:57 +0000] "GET /sleepwalker-como-funciona-la-puerta-trasera-pasiva-que-despierta-con-un-solo-paq/ HTTP/1.1" 200 4994 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36"
194.195.91.7 - qr.javierin.com - - [19/Sep/2026:19:08:17 +0000] "GET /category/virtualizacion/ HTTP/1.1" 200 4130 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
🇩🇪
webanyone
2026-09-19 18:46:42
(1 day ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
🇩🇪
check-the-sum.fr
2026-09-19 15:44:28
(1 day ago)
Port Scanning
Port Scan
🇩🇪
pltcldvlpr
2026-09-19 14:07:32
(2 days ago)
CMS/framework probe: 194.195.91.7 - - [19/Sep/2026:16:07:31 +0200] "GET /.env HTTP/1.1" 301 178 "-" ...
show more
CMS/framework probe: 194.195.91.7 - - [19/Sep/2026:16:07:31 +0200] "GET /.env HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:106.0) Gecko/20100101 Firefox/106.0" asn=206092 org="F.N.S. HOLDINGS LIMITED" country=SE
...
show less
Web App Attack
🇦🇺
AWW-Admin
2026-07-17 13:07:14
(2 months ago)
(wordpress) Failed wordpress login from 194.195.91.7 (SE/Sweden/-)
Brute-Force
Anonymous
2026-07-17 05:07:04
(2 months ago)
[email.tmg.gr] wp-login-spray-user: sites=tmg.gr; samples=target_user=tmgnikos | distinct_ips=23 | t ...
show more
[email.tmg.gr] wp-login-spray-user: sites=tmg.gr; samples=target_user=tmgnikos | distinct_ips=23 | total_fails=57
show less
Hacking
Web App Attack
🇦🇹
penguin-solutions.at
2026-07-07 11:14:23
(2 months ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇩🇪
ghostwarriors
2026-07-07 06:51:26
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-27 15:54:04
(2 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-06-27 10:56:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 194.195.91.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.195.91.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 06:56:32.865514 2026] [security2:error] [pid 29163:tid 29163] [client 194.195.91.7:33025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heytechiesshow.com"] [uri "/admin/.env"] [unique_id "aj-sYA9yv6O7gJjIG0WdOAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-27 10:28:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 194.195.91.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.195.91.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 06:28:06.232247 2026] [security2:error] [pid 25164:tid 25164] [client 194.195.91.7:49027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lyounglaw.com"] [uri "/wp-config.php"] [unique_id "aj-ltpXpOf3Q-OWJI9T2rgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-27 07:56:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 194.195.91.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.195.91.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 03:56:03.638001 2026] [security2:error] [pid 6386:tid 6386] [client 194.195.91.7:59481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.iwsa.info"] [uri "/config/parameters.yml"] [unique_id "aj-CE0WgTxTCzcIWFwNRiwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Mykola Spesivtsev
2026-06-27 07:45:25
(2 months ago)
HTTP Tarpit detected bot activity:TargetPort:80, Path:/.env.example, Method:GET, UA:Mozilla/5.0 (Win ...
show more
HTTP Tarpit detected bot activity:TargetPort:80, Path:/.env.example, Method:GET, UA:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/124.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
Bad Web Bot
🇪🇸
librebit
2026-06-27 05:31:53
(2 months ago)
Brute force
Brute-Force