๐ฌ๐ท
setupgr
2026-06-17 08:36:42
(22 minutes ago)
(mod_security) mod_security (id:1000001) triggered by 203.25.124.51 (JP/Japan/Osaka/Osaka/-/[AS13740 ...
show more
(mod_security) mod_security (id:1000001) triggered by 203.25.124.51 (JP/Japan/Osaka/Osaka/-/[AS137409 GSLNETWORKS-AS-AP GSL Networks Pty LTD]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jun 17 11:36:40.409177 2026] [security2:error] [pid 2280080:tid 2280107] [client 203.25.124.51:34899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp-load.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "93"] [id "1000001"] [msg "Bad file blocked: /wp-content/languages/plugins/wp-load.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.fashionfragonard.gr"] [uri "/wp-content/languages/plugins/wp-load.php"] [unique_id "ajJcmMsskNLCXd8cDXSjOQAAAAA"]
show less
Port Scan
๐ง๐ท
Halux
2026-06-17 08:12:58
(46 minutes ago)
203.25.124.51 Probing protected path or service
Web App Attack
๐ฌ๐ท
setupgr
2026-06-16 08:24:50
(1 day ago)
(mod_security) mod_security (id:1000001) triggered by 203.25.124.51: 1 in the last 86400 secs; Ports ...
show more
(mod_security) mod_security (id:1000001) triggered by 203.25.124.51: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Tue Jun 16 11:24:47.781217 2026] [security2:error] [pid 2210176:tid 2210246] [client 203.25.124.51:29363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp-load.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "93"] [id "1000001"] [msg "Bad file blocked: /wp-content/wp-load.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.cpanagiotou.gr"] [uri "/wp-content/wp-load.php"] [unique_id "ajEIT40pb6dkgQfaMdBi7gAAAQE"]
show less
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-06-16 06:02:41
(1 day ago)
203.25.124.51 - - [16/Jun/2026:09:02:40 +0300] "GET /wp-includes/assets/ HTTP/1.1" 404 708 "-" "Go-h ...
show more
203.25.124.51 - - [16/Jun/2026:09:02:40 +0300] "GET /wp-includes/assets/ HTTP/1.1" 404 708 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-06-16 04:26:23
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-197)
show less
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-06-16 03:35:56
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2026-06-16 01:25:07
(1 day ago)
203.25.124.51 - - [16/Jun/2026:04:25:06 +0300] "GET /wp-content/uploads/2025/ HTTP/1.1" 404 706 "-" ...
show more
203.25.124.51 - - [16/Jun/2026:04:25:06 +0300] "GET /wp-content/uploads/2025/ HTTP/1.1" 404 706 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐ฉ๐ช
Lino Project
2026-06-15 21:59:33
(1 day ago)
203.25.124.51 - - [15/Jun/2026:23:59:29 +0200] "GET /1.php HTTP/1.1" 302 411 "-" "Go-http-client/1.1 ...
show more
203.25.124.51 - - [15/Jun/2026:23:59:29 +0200] "GET /1.php HTTP/1.1" 302 411 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-15 20:12:35
(1 day ago)
203.25.124.51 - - [15/Jun/2026:23:12:34 +0300] "GET /wp-content/plugins/hello.php HTTP/1.1" 404 708 ...
show more
203.25.124.51 - - [15/Jun/2026:23:12:34 +0300] "GET /wp-content/plugins/hello.php HTTP/1.1" 404 708 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
203.25.124.51 - - [15/Jun/2026:23:12:35 +0300] "GET /wp-includes/Text/about.php HTTP/1.1" 404 708 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
...
show less
Web App Attack
๐ฌ๐ท
setupgr
2026-06-15 19:51:28
(1 day ago)
(mod_security) mod_security (id:1000001) triggered by 203.25.124.51: 1 in the last 86400 secs; Ports ...
show more
(mod_security) mod_security (id:1000001) triggered by 203.25.124.51: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Mon Jun 15 22:51:25.814129 2026] [security2:error] [pid 1917021:tid 1917206] [client 203.25.124.51:62509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/1.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "92"] [id "1000001"] [msg "Bad file blocked: /1.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.doityourself.gr"] [uri "/1.php"] [unique_id "ajBXvQ799xbSHUG5HIrgEAAAAMg"]
show less
Port Scan
๐ฆ๐น
Pingger Shikkoken
2026-06-15 11:31:17
(1 day ago)
2026-06-15T11:31:17+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT= MAC=b6:ab:74:e6 ...
show more
2026-06-15T11:31:17+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT= MAC=b6:ab:74:e6:2e:14:84:03:28:62:88:32:08:00 SRC=203.25.124.51 DST=152.53.50.28 LEN=60 TOS=0x00 PREC=0x60 TTL=53 ID=939 DF PROTO=TCP SPT=65445 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0 2026-06-15T11:31:18+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT= MAC=b6:ab:74:e6:2e:14:84:03:28:62:88:32:08:00 SRC=203.25.124.51 DST=152.53.50.28 LEN=60 TOS=0x00 PREC=0x60 TTL=53 ID=940 DF PROTO=TCP SPT=65445 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0 2026-06-15T11:31:20+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT= MAC=b6:ab:74:e6:2e:14:84:03:28:62:88:32:08:00 SRC=203.25.124.51 DST=152.53.50.28 LEN=60 TOS=0x00 PREC=0x60 TTL=53 ID=941 DF PROTO=TCP SPT=65445 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0 ...
show less
Hacking
Bad Web Bot
Anonymous
2026-06-15 10:14:35
(1 day ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ท
masterguru
2026-06-15 09:36:09
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-195)
show less
Bad Web Bot
๐ซ๐ท
LRob.fr
2026-06-15 06:45:04
(2 days ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ฉ๐ช
todix
2026-06-14 12:21:48
(2 days ago)
Web App Attack Exploid from 203.25.124.51
Web App Attack