๐ฎ๐ช
AutosOnShow
2026-09-27 19:40:07
(12 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-27 19:39:24.936 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-26 07:18:05
(2 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-26 07:17:50.059 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-25 22:18:06
(2 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-25 22:17:47.126 |
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 08:53:03
(6 days ago)
20 attempts against mh_ha-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
bps-statistics
2026-06-17 21:23:08
(3 months ago)
WP Login Scan Activities: "2026-06-18T04:23:08.231+07:00" "/wp-login.php" "195.63.27.144" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-06-18T04:23:08.231+07:00" "/wp-login.php" "195.63.27.144" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
show less
Web App Attack
๐จ๐ญ
backslash
2026-05-28 12:03:00
(3 months ago)
block ruleset 486D2EE5E731CC049D1E480D68D04DFFE28AADF1
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-18 18:24:15
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 14:24:07.865727 2026] [security2:error] [pid 3710:tid 3710] [client 195.63.27.144:45948] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||starcrestsales.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "starcrestsales.com"] [uri "/wp-login.php"] [unique_id "agtZRx93pws-PIeAR1PRPgAAABM"], referer: https://starcrestsales.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-28 22:05:21
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-27.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
FeG Deutschland
2026-04-23 17:05:06
(5 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 13:29:33
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 09:29:26.661958 2026] [security2:error] [pid 28998:tid 28998] [client 195.63.27.144:40916] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.schlegelcreative.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.schlegelcreative.com"] [uri "/wp-login.php"] [unique_id "abQRNrGpe11hMzyzsR2qEQAAAAw"], referer: https://schlegelcreative.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
Mr.Singh
2026-03-13 12:30:31
(6 months ago)
NFT blocked 195.63.27.144 after 3 rejections on 13-Mar-2026.
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-11 21:03:53
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 17:03:46.734553 2026] [security2:error] [pid 31489:tid 31489] [client 195.63.27.144:28474] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.centrodentalsindolor.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.centrodentalsindolor.com"] [uri "/wp-login.php"] [unique_id "abHYssCxDkoWYPQzSgCWKwAAABs"], referer: https://centrodentalsindolor.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-10 15:52:06
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 11:52:00.195677 2026] [security2:error] [pid 10239:tid 10239] [client 195.63.27.144:52212] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.indiahouseportland.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.indiahouseportland.com"] [uri "/wp-login.php"] [unique_id "abA-IEjUQKbQNZdMJNWQJwAAAAA"], referer: https://www.indiahouseportland.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 08:00:08
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.27.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 02:59:55.386928 2026] [security2:error] [pid 14039:tid 14039] [client 195.63.27.144:34130] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||joevallone.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "joevallone.com"] [uri "/wp-login.php"] [unique_id "aak3-61eC84BGU9DL0AmSwAAAAQ"], referer: http://joevallone.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack