๐ฎ๐ช
AutosOnShow
2026-09-25 13:17:05
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-25 13:16:21.563 |
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-23 00:20:15
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-23 00:18:08
(4 days ago)
195.63.25.197 - - [23/Sep/2026:02:18:04 +0200] "GET / HTTP/1.1" 200 5437 "-" "Mozilla/5.0 (Windows N ...
show more
195.63.25.197 - - [23/Sep/2026:02:18:04 +0200] "GET / HTTP/1.1" 200 5437 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
195.63.25.197 - - [23/Sep/2026:02:18:04 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 459 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
195.63.25.197 - - [23/Sep/2026:02:18:04 +0200] "POST / HTTP/1.1" 200 1313 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
195.63.25.197 - - [23/Sep/2026:02:18:04 +0200] "POST /wp-json/batch/v1 HTTP/1.1" 403 459 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
195.63.25.197 - - [23/Sep/2026:02:18:04 +0200] "GET /?wpcbb1ec3a1f HTTP/1.1" 200 1345 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebK
show less
Web App Attack
Hacking
๐ฎ๐ช
AutosOnShow
2026-09-22 13:21:05
(4 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-22 13:20:15.821 |
Web App Attack
๐ซ๐ท
dynamix
2026-09-21 09:01:19
(6 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 06:15:28
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 02:15:24.699698 2026] [security2:error] [pid 25118:tid 25118] [client 195.63.25.197:18054] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||salernospizza.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "salernospizza.com"] [uri "/wp-login.php"] [unique_id "aoabfGq9mRTmpAXxt8gEFAAAAAA"], referer: https://salernospizza.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-06-27 04:13:40
(3 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฎ๐ฉ
bps-statistics
2026-06-17 01:18:37
(3 months ago)
WP Login Scan Activities: "2026-06-17T08:18:37.379+07:00" "/wp-login.php" "195.63.25.197" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-06-17T08:18:37.379+07:00" "/wp-login.php" "195.63.25.197" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
show less
Web App Attack
๐จ๐ญ
backslash
2026-05-23 08:36:00
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-14 05:44:05
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 01:43:57.713287 2026] [security2:error] [pid 7800:tid 7820] [client 195.63.25.197:52582] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kettlehill.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kettlehill.com"] [uri "/wp-login.php"] [unique_id "abT1nRSQDFmzFtpX5A__1wAAAVI"], referer: https://kettlehill.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 22:59:05
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 18:58:58.873226 2026] [security2:error] [pid 951:tid 951] [client 195.63.25.197:31736] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||arriagarealestate.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "arriagarealestate.com"] [uri "/wp-login.php"] [unique_id "abSWsuf-PzkKFUL78MytSgAAABE"], referer: https://arriagarealestate.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 22:27:34
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 18:27:26.957939 2026] [security2:error] [pid 3976:tid 3976] [client 195.63.25.197:39406] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||iconconstructors.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "iconconstructors.com"] [uri "/wp-login.php"] [unique_id "abM9zhqXgp-jQPuSjcw0uQAAAAs"], referer: http://iconconstructors.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 00:47:15
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 20:47:08.737532 2026] [security2:error] [pid 6357:tid 6357] [client 195.63.25.197:58220] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lbee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lbee.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abINDNdzPs1jUCsLOIuLKQAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-07 01:59:49
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.25.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 20:59:45.302386 2026] [security2:error] [pid 5637:tid 5637] [client 195.63.25.197:34914] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.digi-estudio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.digi-estudio.com"] [uri "/wp-login.php"] [unique_id "aauGkeU06sWp25JI7b65tAAAAAI"], referer: http://digi-estudio.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack