๐ฎ๐ฉ
David Koswari
2026-09-24 05:19:00
(5 days ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 21:59:21
(6 days ago)
Auto-ban: 201 malicious requests on 2026-09-21 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 201 malicious requests on 2026-09-21 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 16:24:16
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 195.181.172.203 (unn-195-181-172-203.datapacket ...
show more
(mod_security) mod_security (id:225170) triggered by 195.181.172.203 (unn-195-181-172-203.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:24:08.079275 2026] [security2:error] [pid 32398:tid 32398] [client 195.181.172.203:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ruralcommunitycare.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ruralcommunitycare.org"] [uri "/wp-json/wp/v2/users"] [unique_id "arKrqBqcPQ3qhx4ne1ZsxAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-21 16:06:40
(1 week ago)
AetherFox VoidGuard detected: [Mon Sep 21 16:06:39.404083 2026] [authz_core:error] [pid 3389095:tid ...
show more
AetherFox VoidGuard detected: [Mon Sep 21 16:06:39.404083 2026] [authz_core:error] [pid 3389095:tid 3389113] [client 195.181.172.203:51808] AH01630: client denied by server configuration: proxy:https://hq.draconigen.net.dedivirt4209.your-server.de/
[Mon Sep 21 16:06:39.404276 2026] [authz_core:error] [pid 3389095:tid 3389113] [client 195.181.172.203:51808] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Mon Sep 21 16:06:39.970460 2026] [authz_core:error] [pid 3389095:tid 3389105] [client 195.181.172.203:50251] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Mon Sep 21 16:06:40.312611 2026] [authz_core:error] [pid 3389095:tid 3389107] [client 195.181.172.203:57151] AH01630: client denied by server configuration: proxy:https://hq.draconigen.net.dedivirt4209.your-server.de/api/v1/execute
[Mon Sep 21 16:06:40.312781 2026] [authz_core:error] [pid 3389095:tid 3389107] [client 195.181.172.203:57151] AH01
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
abuse-detection
2026-09-21 15:57:47
(1 week ago)
Web security detection (wordpress-rest-user-enum); path=/wp-json/wp/v2/users; status=404
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-21 14:54:32
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 60068 (Datacamp Limited) ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 60068 (Datacamp Limited)
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-json/batch/v1
Timestamp: 2026-09-21T14:36:22Z
Ray ID: a3e9cd430a408ea8
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ต๐ฑ
Budyn
2026-09-21 14:01:16
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: k8s.dont-eat-the-pudding.online | URI: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: {"requests":[{"method":"POST","path":"/wp/v2/posts","body":{"author__not_in":["1) UNION SELECT user_login,user_pass FROM wp_users--"]}}]}
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Webhoster
2026-09-21 13:52:18
(1 week ago)
CrowdSec detected crowdsecurity/http-cve-probing on a monitored service.
Web App Attack
๐บ๐ธ
[email protected]
2026-09-21 13:09:22
(1 week ago)
CrowdSec ban: crowdsecurity/http-cve-probing on homeass.anomaly.cx (duration 4h)
Hacking
Web App Attack
๐ฌ๐ง
f3sc
2026-09-21 12:54:25
(1 week ago)
195.181.172.203 - - [21/Sep/2026:10:12:25 +0100] "POST /api/v1/execute HTTP/1.1" 403 6293 "-" "Mozil ...
show more
195.181.172.203 - - [21/Sep/2026:10:12:25 +0100] "POST /api/v1/execute HTTP/1.1" 403 6293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
195.181.172.203 - - [21/Sep/2026:13:54:24 +0100] "POST /api/v1/execute HTTP/1.1" 403 6293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Port Scan
Hacking
Web App Attack
๐ฉ๐ช
janbro
2026-09-21 12:21:45
(1 week ago)
Automated web application attack detected.
Port Scan
Hacking
Web App Attack
๐ฉ๐ช
Carsten
2026-09-21 10:41:07
(1 week ago)
POST [api/v1/execute]
Port Scan
๐ต๐ฑ
Budyn
2026-09-21 09:44:28
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: idp.astropot.store | URI: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: {"requests":[{"method":"POST","path":"/wp/v2/posts","body":{"author__not_in":["1) UNION SELECT user_login,user_pass FROM wp_users--"]}}]}
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 08:48:08
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 195.181.172.203 (unn-195-181-172-203.datapacket ...
show more
(mod_security) mod_security (id:225170) triggered by 195.181.172.203 (unn-195-181-172-203.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 04:48:02.465749 2026] [security2:error] [pid 26648:tid 26648] [client 195.181.172.203:61597] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.taptaptennis.abecasis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.taptaptennis.abecasis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arDvQhAqwC8nNtO4GcU5JQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-21 08:36:03
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
Exploited Host
Web App Attack