๐ฉ๐ช
pltcldvlpr
2026-09-29 06:35:28
(3 days ago)
CMS/framework probe: 194.5.53.91 - - [29/Sep/2026:08:35:27 +0200] "GET /wp-login.php HTTP/1.1" 403 5 ...
show more
CMS/framework probe: 194.5.53.91 - - [29/Sep/2026:08:35:27 +0200] "GET /wp-login.php HTTP/1.1" 403 564 "https://wordpress.org/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Edg/121.0.2277.83" asn=206092 org="F.N.S. HOLDINGS LIMITED" country=FR
...
show less
Web App Attack
๐ฉ๐ช
Marc
2026-09-28 22:52:00
(3 days ago)
194.5.53.91 - - [29/Sep/2026:00:41:09 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fsaatschule ...
show more
194.5.53.91 - - [29/Sep/2026:00:41:09 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fsaatschule.de%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 11962 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/122.0" 194.5.53.91 - - [29/Sep/2026:00:48:00 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fsaatschule.de%2Fwp-admin%2Fprofile.php&reauth=1 HTTP/1.1" 200 11961 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.85 Safari/537.36" 194.5.53.91 - - [29/Sep/2026:00:48:03 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fsaatschule.de%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 6880 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/120.0.1" 194.5.53.91 - - [29/Sep/2026:00:51:51 +0200] "POST /wp-login.php HTTP/1.1" 403 17934 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like G
show less
Brute-Force
Web App Attack
Anonymous
2026-09-27 12:28:33
(5 days ago)
[PathScanning] Path scanning/probing detected: WordPress admin probe (path: /wp-admin/index.php)
Port Scan
Hacking
๐ฉ๐ช
FeG Deutschland
2026-09-26 06:05:54
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฉ๐ช
tikket
2026-08-15 16:35:34
(1 month ago)
Automated honeypot report: fail2ban 'caddy-honeypot' ban. Source probed honeypot/recon endpoints on ...
show more
Automated honeypot report: fail2ban 'caddy-honeypot' ban. Source probed honeypot/recon endpoints on void.xn--q9jyb4c.
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
NullBlue
2026-08-03 13:51:34
(1 month ago)
Web app attack: scanning for secrets/exploits (.env/.git/PHPUnit CVE). Captured by NullBlue67 honeyp ...
show more
Web app attack: scanning for secrets/exploits (.env/.git/PHPUnit CVE). Captured by NullBlue67 honeypot.
show less
Hacking
Web App Attack
๐บ๐ธ
Vianpyro
2026-08-01 18:23:06
(2 months ago)
Honeypot: 8 request(s) in 2 min. Paths: /app/config/, /config/production.json, /wp-config.php, /admi ...
show more
Honeypot: 8 request(s) in 2 min. Paths: /app/config/, /config/production.json, /wp-config.php, /admin/api/config. Method(s): GET. UA: python-httpx/0.28.1. ASN: 206092 (VPN Consumer Paris, France).
show less
Web App Attack
Bad Web Bot
Hacking
Brute-Force
๐ฉ๐ช
BlueWire Hosting
2026-07-15 01:29:08
(2 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 14:22:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 194.5.53.91 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.53.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 10:22:29.600825 2026] [security2:error] [pid 13088:tid 13088] [client 194.5.53.91:36179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debbiegarner.com"] [uri "/.git/"] [unique_id "aiA4pfYyuPNQFE6jLF5L7wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-03 13:05:12
(3 months ago)
Abuse Detected (4)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 12:17:55
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 194.5.53.91 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.53.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 08:17:49.370539 2026] [security2:error] [pid 19101:tid 19101] [client 194.5.53.91:41687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leesart.net"] [uri "/.git/"] [unique_id "aiAbbdli6pOWivey3fZqVAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-03 12:15:32
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-03 11:17:26
(3 months ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 10:57:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 194.5.53.91 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.53.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 06:57:48.698189 2026] [security2:error] [pid 11917:tid 11917] [client 194.5.53.91:29667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thorsander.com"] [uri "/.git/HEAD"] [unique_id "aiAIrHO-k3kQv-YLPtihGQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-05-27 19:11:00
(4 months ago)
Attaque distribuรฉe subnet
DDoS Attack
Web App Attack