๐ฉ๐ช
Marc
2026-09-28 22:47:35
(4 hours ago)
194.5.53.85 - - [29/Sep/2026:00:39:39 +0200] "POST /wp-login.php HTTP/1.1" 403 17931 "https://saatsc ...
show more
194.5.53.85 - - [29/Sep/2026:00:39:39 +0200] "POST /wp-login.php HTTP/1.1" 403 17931 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.85 Safari/537.36" 194.5.53.85 - - [29/Sep/2026:00:40:21 +0200] "POST /wp-login.php HTTP/1.1" 403 17930 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36" 194.5.53.85 - - [29/Sep/2026:00:47:20 +0200] "POST /wp-login.php HTTP/1.1" 403 17937 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36" 194.5.53.85 - - [29/Sep/2026:00:47:29 +0200] "POST /wp-login.php HTTP/1.1" 403 12852 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Edg/121.0.2277.83" 194.5.53.85 - - [29/Sep/2026:00:47:33
show less
Brute-Force
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-27 02:20:21
(2 days ago)
Zombie network / Bot scanner detected:
[GET] /wp-admin/
[GET] /wp-login.php
UA: Mozilla/5.0 (Macin ...
show more
Zombie network / Bot scanner detected:
[GET] /wp-admin/
[GET] /wp-login.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.1.15
show less
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-26 20:25:25
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 16:57:06
(3 weeks ago)
(mod_security) mod_security (id:220150) triggered by 194.5.53.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:220150) triggered by 194.5.53.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:57:00.253941 2026] [security2:error] [pid 19261:tid 19261] [client 194.5.53.85:43507] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:C. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||crowleywoodworking.com|F|2"] [data "')/**/and/**/('wzqkke'='wzqkke'/**/union/**/all/**/select/**/'fthbieoczmehemrfkwucozjmidfhimkt'--/**/9n3f2m"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "crowleywoodworking.com"] [uri "/"] [unique_id "apmm3P_GETxDAXaiU-U9_gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tikket
2026-08-15 16:35:52
(1 month ago)
Automated honeypot report: fail2ban 'caddy-honeypot' ban. Source probed honeypot/recon endpoints on ...
show more
Automated honeypot report: fail2ban 'caddy-honeypot' ban. Source probed honeypot/recon endpoints on void.xn--q9jyb4c.
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
NullBlue
2026-08-03 13:51:36
(1 month ago)
Web app attack: scanning for secrets/exploits (.env/.git/PHPUnit CVE). Captured by NullBlue67 honeyp ...
show more
Web app attack: scanning for secrets/exploits (.env/.git/PHPUnit CVE). Captured by NullBlue67 honeypot.
show less
Hacking
Web App Attack
๐บ๐ธ
Vianpyro
2026-08-01 18:24:26
(1 month ago)
Honeypot: 6 request(s) in 1 min. Paths: /secrets.json, /storage/logs/, /api/env. Method(s): GET. UA: ...
show more
Honeypot: 6 request(s) in 1 min. Paths: /secrets.json, /storage/logs/, /api/env. Method(s): GET. UA: python-httpx/0.28.1. ASN: 206092 (VPN Consumer Paris, France).
show less
Web App Attack
Bad Web Bot
Hacking
๐จ๐ฆ
DRI
2026-07-24 11:31:19
(2 months ago)
Web attack/Malicious activity detected
Web App Attack
๐ต๐ฑ
mscode.pl
2026-07-19 02:07:40
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: BLOCK
ASN: 206092 (F.N.S. HOLDINGS ...
show more
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: BLOCK
ASN: 206092 (F.N.S. HOLDINGS LIMITED)
Protocol: HTTP/1.1 (GET method)
Zone: mscode.pl
Endpoint: /media/system/js/core.js
UA: Go-http-client/1.1
show less
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-07-15 01:27:38
(2 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฉ๐ช
Lino Project
2026-07-15 00:33:22
(2 months ago)
194.5.53.85 - - [15/Jul/2026:02:33:21 +0200] "GET /wp-content/plugins/so-pinyin-slugs/inc/main_json. ...
show more
194.5.53.85 - - [15/Jul/2026:02:33:21 +0200] "GET /wp-content/plugins/so-pinyin-slugs/inc/main_json.php HTTP/2.0" 404 56308 "http://www.macubedrone.com/wp-content/plugins/so-pinyin-slugs/inc/main_json.php" "Go-http-client/2.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-10 02:31:36
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-06-09 20:59:37
(3 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-06-09 16:31:32
(3 months ago)
Multiple, malicious web requests detected
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-03 16:11:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 194.5.53.85 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.53.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 12:11:01.729376 2026] [security2:error] [pid 8518:tid 8525] [client 194.5.53.85:64307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rudimentseq.com"] [uri "/.git/HEAD"] [unique_id "aiBSFTG851-ijmor7gKlkgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack