Anonymous
2026-10-01 06:16:17
(2 days ago)
[Thu Oct 01 08:16:16.328411 2026] [proxy_fcgi:error] [pid 21224:tid 21267] [client 207.175.70.189:38 ...
show more
[Thu Oct 01 08:16:16.328411 2026] [proxy_fcgi:error] [pid 21224:tid 21267] [client 207.175.70.189:38076] AH01071: Got error 'Primary script unknown'
[Thu Oct 01 08:16:16.354821 2026] [proxy_fcgi:error] [pid 1778:tid 1898] [client 207.175.70.189:38110] AH01071: Got error 'Primary script unknown'
[Thu Oct 01 08:16:16.473156 2026] [proxy_fcgi:error] [pid 21224:tid 21255] [client 207.175.70.189:38076] AH01071: Got error 'Primary script unknown'
[Thu Oct 01 08:16:16.484991 2026] [proxy_fcgi:error] [pid 21224:tid 21257] [client 207.175.70.189:38076] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
π©πͺ
ger-stg-sifi1
2026-10-01 06:06:09
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
raph
2026-10-01 00:56:41
(2 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2026-09-30 19:21:15
(2 days ago)
(PERMBLOCK) 207.175.70.189 (BE/Belgium/Brussels Capital/Brussels/189.70.175.207.bc.googleusercontent ...
show more
(PERMBLOCK) 207.175.70.189 (BE/Belgium/Brussels Capital/Brussels/189.70.175.207.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
Anonymous
2026-09-30 17:30:47
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-30 17:13:55
(2 days ago)
[Wed Sep 30 19:13:53.808003 2026] [proxy_fcgi:error] [pid 1449:tid 1603] [client 207.175.70.189:3944 ...
show more
[Wed Sep 30 19:13:53.808003 2026] [proxy_fcgi:error] [pid 1449:tid 1603] [client 207.175.70.189:39446] AH01071: Got error 'Primary script unknown'
[Wed Sep 30 19:13:53.833769 2026] [proxy_fcgi:error] [pid 1449:tid 1606] [client 207.175.70.189:39446] AH01071: Got error 'Primary script unknown'
[Wed Sep 30 19:13:54.387138 2026] [proxy_fcgi:error] [pid 8657:tid 8690] [client 207.175.70.189:39468] AH01071: Got error 'Primary script unknown'
[Wed Sep 30 19:13:54.451176 2026] [proxy_fcgi:error] [pid 8829:tid 9015] [client 207.175.70.189:39440] AH01071: Got error 'Primary script unknown'
[Wed Sep 30 19:13:54.520454 2026] [proxy_fcgi:error] [pid 1449:tid 1595] [client 207.175.70.189:39446] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
π«π·
Little Iguana
2026-09-30 12:40:06
(3 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
π³π±
Site.eu
2026-09-30 12:33:45
(3 days ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
snhosting
2026-09-30 12:16:28
(3 days ago)
207.175.70.189 - - [30/Sep/2026:14:16:03 +0200] "GET /static../.env HTTP/2.0" 200 1601 "-" "Mozilla/ ...
show more
207.175.70.189 - - [30/Sep/2026:14:16:03 +0200] "GET /static../.env HTTP/2.0" 200 1601 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
207.175.70.189 - - [30/Sep/2026:14:16:03 +0200] "GET /.env.save HTTP/2.0" 200 1606 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
207.175.70.189 - - [30/Sep/2026:14:16:03 +0200] "GET /media../.env HTTP/2.0" 200 1606 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
207.175.70.189 - - [30/Sep/2026:14:16:03 +0200] "GET /files../.env HTTP/2.0" 200 1606 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
207.175.70.189 - - [30/Sep/2026:14:16:03 +0200] "GET /assets../.env HTTP/2.0" 200 1601 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
π©πͺ
itsolon
2026-09-30 12:10:05
(3 days ago)
[30/Sep/2026:14:10:04 +0200] 179077020420.671933 207.175.70.189 0 217.154.7.177 443
[30/Sep/2026:14: ...
show more
[30/Sep/2026:14:10:04 +0200] 179077020420.671933 207.175.70.189 0 217.154.7.177 443
[30/Sep/2026:14:10:04 +0200] 179077020432.949522 207.175.70.189 0 217.154.7.177 443
[30/Sep/2026:14:10:04 +0200] 179077020411.781385 207.175.70.189 0 217.154.7.177 443
[30/Sep/2026:14:10:04 +0200] 179077020412.349074 207.175.70.189 0 217.154.7.177 443
[30/Sep/2026:14:10:04 +0200] 179077020476.509040 207.175.70.189 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π©πͺ
Hazzard
2026-09-30 11:11:33
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
π³π±
Alt255
2026-09-30 11:11:07
(3 days ago)
[ti-26al] Excessive 404 errors (web scanning): 33 suspicious requests detected by fail2ban jail apac ...
show more
[ti-26al] Excessive 404 errors (web scanning): 33 suspicious requests detected by fail2ban jail apache-404. Example: 207.175.70.189 - - [30/Sep/2026:13:10:45 +0200] "GET /sign-in HTTP/1.1" 404 2065 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
207.175.70.189 - - [30/Sep/2026:13:10:45 +0200] "GET /user/login HTTP/1.1" 404 2065 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
207.175.70.189 - - [30/Sep/2026:13:10:45 +0200] "GET /auth/login HTTP/1.1" 404 2065 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
207.175.70.189 - - [30/Sep/2026:13:10:45 +0200] "GET /signin HTTP/1.1" 4
...
show less
Bad Web Bot
Web App Attack
π©πͺ
rh24
2026-09-30 10:27:02
(3 days ago)
(badbots) Bad bot user-agent [redacted] from 207.175.70.189 (BE/Belgium/189.70.175.207.bc.googleuser ...
show more
(badbots) Bad bot user-agent [redacted] from 207.175.70.189 (BE/Belgium/189.70.175.207.bc.googleusercontent.com)
show less
Hacking
Anonymous
2026-09-30 10:00:59
(3 days ago)
Fail2Ban nginx-scanner-critical: critical web exploit scan
Web App Attack
π³π±
maxxsense
2026-09-30 09:54:18
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 207.175.70.189 (BE/Belgium/189.70.175.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 207.175.70.189 (BE/Belgium/189.70.175.207.bc.googleusercontent.com)
show less
SQL Injection