๐ฎ๐ช
AutosOnShow
2026-09-29 12:08:05
(2 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-29 12:07:15.550 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-27 17:08:05
(4 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-27 17:07:31.661 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-25 09:29:05
(6 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-25 09:28:51.066 |
Web App Attack
๐บ๐ธ
Vianpyro
2026-08-11 10:18:08
(1 month ago)
Honeypot: 6 request(s) in 0 min. Paths: /.env.local, /config.json, /.git/HEAD. Method(s): GET. UA: M ...
show more
Honeypot: 6 request(s) in 0 min. Paths: /.env.local, /config.json, /.git/HEAD. Method(s): GET. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko). ASN: 200373 (3xK Tech GmbH).
show less
Web App Attack
Bad Web Bot
Hacking
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-08 14:05:03
(1 month ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-08 13:08:01
(1 month ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-05-12 07:51:32
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฌ๐ท
ggb_st
2026-05-09 00:20:42
(4 months ago)
[2026-05-09 00:20:41] 195.63.16.186 triggered a honeypot. Requested on port 443. URI: /wp-json/gravi ...
show more
[2026-05-09 00:20:41] 195.63.16.186 triggered a honeypot. Requested on port 443. URI: /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings, UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
...
show less
Bad Web Bot
Brute-Force
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-03-14 19:04:18
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 15:04:10.455473 2026] [security2:error] [pid 3259:tid 3259] [client 195.63.16.186:53278] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.centrodentalsindolor.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.centrodentalsindolor.com"] [uri "/wp-login.php"] [unique_id "abWxKtuZKKoQiHeDY2fjNgAAAAo"], referer: https://centrodentalsindolor.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 06:34:47
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 02:34:42.604144 2026] [security2:error] [pid 5825:tid 5825] [client 195.63.16.186:58974] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atame.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abJegk3sEqE4CjtW8wd4MwAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 16:06:32
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 12:06:25.838798 2026] [security2:error] [pid 21648:tid 21670] [client 195.63.16.186:60852] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||apada.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "apada.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abGTAWVaavTcBVdcEDJfpAAAAFE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 15:34:28
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 11:34:24.178057 2026] [security2:error] [pid 9319:tid 9319] [client 195.63.16.186:23640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||purebinary.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "purebinary.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abGLgPtoBljTRd6zHDnzaAAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 19:03:08
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.16.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 14:03:05.426526 2026] [security2:error] [pid 27636:tid 27636] [client 195.63.16.186:28434] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||engineeringarts.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "engineeringarts.com"] [uri "/wp-login.php"] [unique_id "aanTaXjYQZkd_NQBB403PQAAAAc"], referer: https://engineeringarts.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack