[Security Alert] Unauthorized malicious activity detected; IP address has been automatically blocked ...
show more[Security Alert] Unauthorized malicious activity detected; IP address has been automatically blocked and banned. [Method]: GET. [Request]: => /openapi.json [User-Agent]: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36. [OS]: Linux. [IP Address]: 195.63.30.79. [RPS] High overshoot requests per second (RPS). [Date]: 2026-06-13 03:56:29 UTC.
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-27.
show less
(mod_security) mod_security (id:210350) triggered by 195.63.30.79 (-): 1 in the last 300 secs; Ports ...
show more(mod_security) mod_security (id:210350) triggered by 195.63.30.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 05:03:42.082118 2026] [security2:error] [pid 32071:tid 32071] [client 195.63.30.79:19934] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||joeordie.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "joeordie.com"] [uri "/wp-login.php"] [unique_id "abPS7iGQJOQamNBD0wYXZQAAAAk"], referer: http://joeordie.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-12T07:04:04.870734+02:00 zanati wp(sahpa.co.za)[1146756]: Blocked authentication attempt for ...
show more2026-03-12T07:04:04.870734+02:00 zanati wp(sahpa.co.za)[1146756]: Blocked authentication attempt for office from 195.63.30.79
...
show less