π©πͺ
ghostwarriors
2026-09-03 13:50:07
(25 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π΅π±
sledzik1984
2026-09-03 13:47:01
(28 minutes ago)
2026/09/03 15:46:54 [error] 2270719#2270719: *81382 directory index of "/home/web-other/lotnisko/wp- ...
show more
2026/09/03 15:46:54 [error] 2270719#2270719: *81382 directory index of "/home/web-other/lotnisko/wp-content/uploads/" is forbidden, client: 20.65.79.49, server: airport.cma.pl, request: "GET /wp-content/uploads/ HTTP/1.1", host: "www.zlocien.eu.org"
2026/09/03 15:46:59 [error] 2270719#2270719: *81377 directory index of "/home/web-other/lotnisko/wp-content/plugins/woocommerce/" is forbidden, client: 20.65.79.49, server: airport.cma.pl, request: "GET /wp-content/plugins/woocommerce/ HTTP/1.1", host: "www.zlocien.eu.org"
20.65.79.49 - - [03/Sep/2026:15:47:00 +0200] "GET /config/database.php HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Web App Attack
π§πͺ
cmbplf
2026-09-03 13:32:54
(42 minutes ago)
107 requests with url.path *debug.log
107 requests with url.path */debug.log
Brute-Force
Bad Web Bot
π©πͺ
dbmwebdesign
2026-09-03 13:10:04
(1 hour ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-03 13:00:06
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.bak HTTP/1. ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /pathscan-b81c13e6c776-nope.env HTTP/1.1, GET / HTTP/1.1
show less
Hacking
Web App Attack
π«π·
masterguru
2026-09-03 12:41:28
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 11:28:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.65.79.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 20.65.79.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:28:02.397012 2026] [security2:error] [pid 3228:tid 3228] [client 20.65.79.49:44718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.walterceron.com"] [uri "/.hg/store/00manifest.i"] [unique_id "aplZwr1XUbqWYVUEy6heowAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Joop
2026-09-03 10:32:16
(3 hours ago)
2026-09-03 12:32:13 +0200 s7 /app/etc/env.php
Web App Attack
π«π·
dynamix
2026-09-03 10:19:18
(3 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 10:03:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.65.79.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 20.65.79.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 06:03:40.248097 2026] [security2:error] [pid 22197:tid 22197] [client 20.65.79.49:56766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.obramaq.cl"] [uri "/.hg/store/00manifest.i"] [unique_id "aplF_BWC11VUnl5LtPQ3pAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 09:40:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.65.79.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 20.65.79.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:40:00.923435 2026] [security2:error] [pid 14051:tid 14051] [client 20.65.79.49:57374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.m5mindsetcom.indie100.com"] [uri "/wp-config.php.bak"] [unique_id "aplAcNd0DRKijd5pPNyb8AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-03 09:33:23
(4 hours ago)
Brute force login attempts
Hacking
Web App Attack
Brute-Force
Anonymous
2026-09-03 09:28:07
(4 hours ago)
(caddyscan) Scanner path probe from 20.65.79.49 (US/United States/-): 5 in the last 3600 secs; Ports ...
show more
(caddyscan) Scanner path probe from 20.65.79.49 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 20.65.79.49 - - [03/Sep/2026:09:28:05 +0000] "GET /wp-config.php.bak HTTP/1.1"
[REDACTED] 200 2627 20.65.79.49 - - [03/Sep/2026:09:28:05 +0000] "GET /wp-config.php~ HTTP/1.1"
[REDACTED] 200 2627 20.65.79.49 - - [03/Sep/2026:09:28:05 +0000] "GET /wp-config.php.save HTTP/1.1"
[REDACTED] 200 2627 20.65.79.49 - - [03/Sep/2026:09:28:05 +0000] "GET /wp-config.php.orig HTTP/1.1"
[REDACTED] 200 2627 20.65.79.49 - - [03/Sep/2026:09:28:05 +0000] "GET /.env.orig HTTP/1.1"
show less
Port Scan
π©πͺ
Hary74656
2026-09-03 08:57:29
(5 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
π©πͺ
EGP Abuse Dept
2026-09-03 08:56:03
(5 hours ago)
Scanning for web/db/file exploits on knodtablemanner.tafelconfigurator.nl
SQL Injection
Bad Web Bot
Web App Attack