π§π·
Peregrine
2026-06-21 03:13:27
(15 hours ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 2.58.56.131 172.71.95.46 - - [01/Jun/2026:17:38:04 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 2.58.56.131 172.71.95.46 - - [01/Jun/2026:17:38:04 -0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 18193
show less
Bad Web Bot
π§π·
Peregrine
2026-06-19 03:13:41
(2 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 2.58.56.131 172.71.95.46 - - [01/Jun/2026:17:38:04 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 2.58.56.131 172.71.95.46 - - [01/Jun/2026:17:38:04 -0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 18193
show less
Bad Web Bot
π§π·
Peregrine
2026-06-18 03:13:25
(3 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 2.58.56.131 172.71.95.46 - - [01/Jun/2026:17:38:04 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 2.58.56.131 172.71.95.46 - - [01/Jun/2026:17:38:04 -0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 18193
show less
Bad Web Bot
Anonymous
2026-06-16 15:49:12
(5 days ago)
Multiple, malicious web requests detected
Port Scan
Hacking
Anonymous
2026-06-16 13:20:11
(5 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
π©πͺ
maxpower
2026-06-16 09:26:23
(5 days ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 2.58.56.131 (mail.huiles-olives.net): 2 in the last ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 2.58.56.131 (mail.huiles-olives.net): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2.58.56.131 - - [16/Jun/2026:11:26:15 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 309 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "2.58.56.131" host=tikitakaplanet.it
2.58.56.131 - - [16/Jun/2026:11:26:20 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 301 0 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "2.58.56.131" host=tikitakaplanet.it
show less
Port Scan
πΊπΈ
antlac1
2026-06-16 07:52:39
(5 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
π§π·
Peregrine
2026-06-16 03:13:53
(5 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 2.58.56.131 172.71.95.46 - - [01/Jun/2026:17:38:04 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 2.58.56.131 172.71.95.46 - - [01/Jun/2026:17:38:04 -0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 18193
show less
Bad Web Bot
π¦πΊ
paulshipley.com.au
2026-06-16 03:10:38
(5 days ago)
[Tue Jun 16 13:10:37.417357 2026] [security2:error] [pid 197137] [client 2.58.56.131:51606] [client ...
show more
[Tue Jun 16 13:10:37.417357 2026] [security2:error] [pid 197137] [client 2.58.56.131:51606] [client 2.58.56.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/wp-plain.php"] [unique_id "ajC-rZJEnflpHl3Dvm1YZwAAAAw"], referer: www.google.com
...
show less
Web App Attack
π«π·
pm33
2026-06-16 02:47:59
(5 days ago)
Unauthorized connections HTTP 403
Web App Attack
π©πͺ
LRob.fr
2026-06-16 02:00:09
(5 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
π¬π§
OptimusGO
2026-06-16 01:50:36
(5 days ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-16 02:50:36 UTC
Log evidence:
06/16/2026-02:50:35.577363 [**] [1:2400000:4510] ET DROP Spamhaus DROP Listed Traffic Inbound group 1 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 2.58.56.131:54257 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
πΊπΈ
nationaleventpros.com
2026-06-16 01:18:12
(5 days ago)
vulnerability scan
Web App Attack
π¬π§
andypiper
2026-06-16 01:03:10
(5 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
πΊπΈ
agenciahypelab.com.br
2026-06-16 00:53:13
(5 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH