๐ฉ๐ช
FeG Deutschland
2026-09-27 18:26:34
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-21 21:04:34
(2 weeks ago)
[Tue Sep 22 07:04:33.964720 2026] [security2:error] [pid 161905] [client 195.63.18.101:42888] [clien ...
show more
[Tue Sep 22 07:04:33.964720 2026] [security2:error] [pid 161905] [client 195.63.18.101:42888] [client 195.63.18.101] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ccideas.com.au"] [uri "/wp-content/plugins/woo-conditional-shipping-pro/frontend/css/woo-conditional-shipping.css"] [unique_id "arGb4f59LfzraQtEdMTC6QAAAAI"], referer: https://ccideas.com.au/my-account/?action=register
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-03 21:59:12
(2 months ago)
Auto-ban: >3000 req/min op 2026-08-03
Web App Attack
SSH
Hacking
๐ซ๐ท
Tilellit.PRO
2026-05-16 04:44:37
(4 months ago)
Fail2Ban banned 195.63.18.101 for security violations in jail wp-armour. Log: 2026/05/16 04:44:37 [e ...
show more
Fail2Ban banned 195.63.18.101 for security violations in jail wp-armour. Log: 2026/05/16 04:44:37 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 195.63.18.101 | Target: wplogin" , client: 195.63.18.101, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฎ๐น
[email protected]
2026-04-30 01:20:25
(5 months ago)
[Thu Apr 30 03:20:24.815924 2026] [authz_core:error] [pid 299680:tid 299711] [remote 195.63.18.101:5 ...
show more
[Thu Apr 30 03:20:24.815924 2026] [authz_core:error] [pid 299680:tid 299711] [remote 195.63.18.101:50760] AH01630: client denied by server configuration: /var/www/html/MyWeb/Wordpress_www/xmlrpc.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2026-04-28 04:08:56
(5 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 07:35:00
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.18.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.18.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 03:34:54.538235 2026] [security2:error] [pid 16289:tid 16289] [client 195.63.18.101:34446] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.kerrywood.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kerrywood.com"] [uri "/wp-login.php"] [unique_id "abUPnoDP3TEpCd9hwz9NuAAAAAk"], referer: https://kerrywood.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-03-13 01:36:04
(6 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-10 06:59:16
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.18.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.18.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 02:59:11.504206 2026] [security2:error] [pid 25571:tid 25571] [client 195.63.18.101:10916] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ultratecnologia.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ultratecnologia.com"] [uri "/wp-login.php"] [unique_id "aa_BP1C_bJMGSXv7nJ7iBAAAAAE"], referer: https://ultratecnologia.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 18:39:34
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.18.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.18.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 14:39:29.149595 2026] [security2:error] [pid 6989:tid 6989] [client 195.63.18.101:39520] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||daos.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "daos.org"] [uri "/wp-login.php"] [unique_id "aa8T4XNOSCMps1p_EGSD6AAAACQ"], referer: https://daos.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack