๐ฉ๐ช
LRob.fr
2026-06-05 23:00:08
(2 weeks ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-05-24 05:57:41
(1 month ago)
194.32.120.228 - - [24/May/2026:06:57:40 +0100] "GET /cgi-bin/ HTTP/1.1" 404 4149 "-" "Mozilla/5.0 ( ...
show more
194.32.120.228 - - [24/May/2026:06:57:40 +0100] "GET /cgi-bin/ HTTP/1.1" 404 4149 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
show less
Bad Web Bot
๐บ๐ธ
mnsf
2026-05-09 21:05:09
(1 month ago)
Request Overload (123)
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-05-09 16:47:57
(1 month ago)
Aggressive web search of vulnerable pages: /wp-includes/IXR/ /wp-includes/widgets/ /wp-includes/imag ...
show more
Aggressive web search of vulnerable pages: /wp-includes/IXR/ /wp-includes/widgets/ /wp-includes/images/smilies/ /wp-includes/js/crop/ /wp-inclu ...
show less
Web App Attack
๐ต๐ญ
thezelijah
2026-05-09 14:45:00
(1 month ago)
Probing and recon. PHP and config hunting.
Port Scan
Brute-Force
Web App Attack
Hacking
Anonymous
2026-04-02 08:30:09
(2 months ago)
GET wordpress | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ...
show more
GET wordpress | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 OPR/120.0.0.0 | Time: 2026-04-02 08:30:09 UTC
show less
Web App Attack
๐บ๐ธ
mnsf
2026-02-23 14:05:18
(4 months ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-02-23 12:31:30
(4 months ago)
194.32.120.228 - - [23/Feb/2026:14:31:29 +0200] "GET //wp-includes/js/index.php HTTP/1.1" 404 278 "- ...
show more
194.32.120.228 - - [23/Feb/2026:14:31:29 +0200] "GET //wp-includes/js/index.php HTTP/1.1" 404 278 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-02-23 10:14:27
(4 months ago)
194.32.120.228 - - [23/Feb/2026:12:14:25 +0200] "GET //wp-content/plugins/enhanced-text-widget/analy ...
show more
194.32.120.228 - - [23/Feb/2026:12:14:25 +0200] "GET //wp-content/plugins/enhanced-text-widget/analyst/src/403x.php HTTP/1.1" 404 288 "-" "Go-http-client/1.1"
194.32.120.228 - - [23/Feb/2026:12:14:26 +0200] "GET //wp-content/plugins/semrush/x.php HTTP/1.1" 404 288 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-02-20 04:12:45
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-02 06:34:28
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 194.32.120.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 194.32.120.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 02 01:34:22.641838 2026] [security2:error] [pid 20978:tid 20978] [client 194.32.120.228:21117] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||phantomkennels.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "phantomkennels.com"] [uri "/bak/www.sql"] [unique_id "aYBFbjsM6Rcg7PBN6EiD7AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-01-25 20:04:06
(4 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
Penny Packer
2026-01-05 08:54:28
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
mnsf
2026-01-04 12:05:26
(5 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 17:44:10
(6 months ago)
(mod_security) mod_security (id:240000) triggered by 194.32.120.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 194.32.120.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 12:42:47.445384 2025] [security2:error] [pid 1840:tid 1840] [client 194.32.120.228:50197] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||wetlizarddiveteam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "wetlizarddiveteam.com"] [uri "/images/stories/themes.php"] [unique_id "aTRrF99XQcPbVReWb5VneAAAAFs"]
show less
Brute-Force
Bad Web Bot
Web App Attack