๐ฌ๐ท
setupgr
2026-10-03 23:16:01
(6 hours ago)
(wplogin_block) Blocked WP-Login Access Attempt 194.5.53.86 (FR/France/Paris Department/Paris/-/[AS2 ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 194.5.53.86 (FR/France/Paris Department/Paris/-/[AS206092 F.n.s. Holdings Limited]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 194.5.53.86 - - [04/Oct/2026:02:12:03 +0300] "GET /wp-login.php?redirect_to=https%3A%2F%2Fions.gr%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 11547 "https://ions.gr/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36"
show less
Port Scan
๐ฉ๐ช
Marc
2026-09-29 13:24:24
(4 days ago)
194.5.53.86 - - [29/Sep/2026:15:23:00 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fals-arnsbe ...
show more
194.5.53.86 - - [29/Sep/2026:15:23:00 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fals-arnsberg.eu%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 11017 "https://als-arnsberg.eu/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Gecko/20100101 Firefox/118.0.2" 194.5.53.86 - - [29/Sep/2026:15:23:05 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fals-arnsberg.eu%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 5931 "https://als-arnsberg.eu/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36" 194.5.53.86 - - [29/Sep/2026:15:23:11 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fals-arnsberg.eu%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 5931 "https://als-arnsberg.eu/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36" 194.5.53.86 - - [29/Sep/2026:15:23:17 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fals-arnsberg.eu%2Fwp-adm
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2026-09-28 22:46:58
(5 days ago)
194.5.53.86 - - [29/Sep/2026:00:38:43 +0200] "POST /wp-login.php HTTP/1.1" 403 17931 "https://saatsc ...
show more
194.5.53.86 - - [29/Sep/2026:00:38:43 +0200] "POST /wp-login.php HTTP/1.1" 403 17931 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/119.0.1" 194.5.53.86 - - [29/Sep/2026:00:39:50 +0200] "POST /wp-login.php HTTP/1.1" 403 17931 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36" 194.5.53.86 - - [29/Sep/2026:00:41:57 +0200] "POST /wp-login.php HTTP/1.1" 403 17936 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15" 194.5.53.86 - - [29/Sep/2026:00:46:51 +0200] "POST /wp-login.php HTTP/1.1" 403 17932 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Safari/605.1.15" 194.5.53.86 - - [29/Sep/2026:00:46:58 +0200] "POST /wp-login.php HTTP/1.1" 403 12723 "https://saatschu
show less
Brute-Force
Web App Attack
Anonymous
2026-09-27 12:27:38
(6 days ago)
[PathScanning] Path scanning/probing detected: WordPress admin probe (path: /wp-admin/index.php)
Port Scan
Hacking
๐ฉ๐ช
raph
2026-08-18 03:42:01
(1 month ago)
[SQL INJECTION] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(%20AND%20|%2 ...
show more
[SQL INJECTION] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(%20AND%20|%20and%20|%20OR%20|%20or%20).* HTTP/1.1$
show less
SQL Injection
๐ฉ๐ช
tikket
2026-08-15 16:41:07
(1 month ago)
Automated honeypot report: fail2ban 'caddy-honeypot' ban. Source probed honeypot/recon endpoints on ...
show more
Automated honeypot report: fail2ban 'caddy-honeypot' ban. Source probed honeypot/recon endpoints on void.xn--q9jyb4c.
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
NullBlue
2026-08-03 13:51:41
(2 months ago)
Web app attack: scanning for secrets/exploits (.env/.git/PHPUnit CVE). Captured by NullBlue67 honeyp ...
show more
Web app attack: scanning for secrets/exploits (.env/.git/PHPUnit CVE). Captured by NullBlue67 honeypot.
show less
Hacking
Web App Attack
๐บ๐ธ
Vianpyro
2026-08-01 18:22:26
(2 months ago)
Honeypot: 6 request(s) in 435 min. Paths: /config/mail.php, /settings/mail.json, /api/credentials. M ...
show more
Honeypot: 6 request(s) in 435 min. Paths: /config/mail.php, /settings/mail.json, /api/credentials. Method(s): GET. UA: python-httpx/0.28.1. ASN: 206092 (VPN Consumer Paris, France).
show less
Web App Attack
Bad Web Bot
Hacking
๐บ๐ธ
ipblock.com
2026-07-18 03:09:00
(2 months ago)
IPBlock protected site ID [669-fx].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-15 01:24:25
(2 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฉ๐ช
Lino Project
2026-07-15 00:37:43
(2 months ago)
194.5.53.86 - - [15/Jul/2026:02:37:41 +0200] "GET /admin.php HTTP/1.1" 301 673 "http://macubedrone.c ...
show more
194.5.53.86 - - [15/Jul/2026:02:37:41 +0200] "GET /admin.php HTTP/1.1" 301 673 "http://macubedrone.com/admin.php" "Go-http-client/1.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
R.G.
2026-06-10 06:10:58
(3 months ago)
(ScanningForFiles) Scanning for files triggerd 194.5.53.86 (FR/France/-): 10 in the last 600 secs; P ...
show more
(ScanningForFiles) Scanning for files triggerd 194.5.53.86 (FR/France/-): 10 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-03 22:02:18
(4 months ago)
Auto-ban: >3000 req/min op 2026-06-03
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-03 16:20:38
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 194.5.53.86 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.53.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 12:20:31.210733 2026] [security2:error] [pid 25170:tid 25170] [client 194.5.53.86:25757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lordcain.net"] [uri "/.git/config"] [unique_id "aiBUT51e5ZkTArkN63iCEwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 15:29:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 194.5.53.86 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.53.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 11:29:40.736989 2026] [security2:error] [pid 27058:tid 27058] [client 194.5.53.86:42869] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christmasweddingnapkins.com"] [uri "/.git/HEAD"] [unique_id "aiBIZA09VzhUd6Fx4EKlGgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack