πΊπΈ
kosada.com
2026-04-20 10:10:14
(1 month ago)
Web vulnerability probing: /wp-includes/blocks/about.php
Web App Attack
π¬π§
consul.to
2026-04-20 05:10:42
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
Site.eu
2026-04-20 00:42:55
(1 month ago)
Excessive multi-domain requests
Brute-Force
π¬π§
Don Felip
2026-04-19 14:04:50
(1 month ago)
Web Exploiter - Banned by Fail2Ban
Hacking
Web App Attack
π«π·
Baking333
2026-04-19 11:50:13
(1 month ago)
[redacted] 212.30.37.39 - - [19/Apr/2026:12:50:12 +0100] "GET /wp-includes/SimplePie/[redacted] HTTP ...
show more
[redacted] 212.30.37.39 - - [19/Apr/2026:12:50:12 +0100] "GET /wp-includes/SimplePie/[redacted] HTTP/1.1" 301 580 0/134 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" [redacted] 212.30.37.39 - - [19/Apr/2026:12:50:12 +0100] "GET /wp-admin/images/[redacted] HTTP/1.1" 301 568 0/133 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
show less
Bad Web Bot
Web App Attack
π«π·
Baking333
2026-04-18 13:37:40
(1 month ago)
[redacted] 212.30.37.39 - - [18/Apr/2026:14:37:39 +0100] "GET /wp-content/upgrade/[redacted] HTTP/1. ...
show more
[redacted] 212.30.37.39 - - [18/Apr/2026:14:37:39 +0100] "GET /wp-content/upgrade/[redacted] HTTP/1.1" 301 582 0/159 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" [redacted] 212.30.37.39 - - [18/Apr/2026:14:37:39 +0100] "GET /wp-includes/[redacted] HTTP/1.1" 301 562 0/137 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-04-18 05:17:55
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-04-17 19:07:34
(1 month ago)
[redacted] 212.30.37.39 - - [17/Apr/2026:21:07:32 +0200] "GET /wp-admin/js/autoload_classmap.php HTT ...
show more
[redacted] 212.30.37.39 - - [17/Apr/2026:21:07:32 +0200] "GET /wp-admin/js/autoload_classmap.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
[redacted] 212.30.37.39 - - [17/Apr/2026:21:07:32 +0200] "GET /wp-admin/css/colors/ectoplasm/about.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
[redacted] 212.30.37.39 - - [17/Apr/2026:21:07:33 +0200] "GET /wp-admin/css/wp-conflg.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
[redacted] 212.30.37.39 - - [17/Apr/2026:21:07:33 +0200] "GET /wp-admin/images/index.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0"
[redacted] 212.30.37.39 - - [17/Apr/2026:21:07:33 +0200] "GET /wp-admin/js/widgets/cloud.php HTTP/1.1" 404 236
...
show less
Hacking
Web App Attack
π¨π
Origon
2026-04-15 13:55:33
(1 month ago)
http-crawl-non_statics - IP: 212.30.37.39 - time="2026-04-15T15:55:33+02:00" level=info msg="(555f6 ...
show more
http-crawl-non_statics - IP: 212.30.37.39 - time="2026-04-15T15:55:33+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-crawl-non_statics by ip 212.30.37.39 (NL/137409) : 4h ban on Ip 212.30.37.39" module=db
show less
Bad Web Bot
π©πͺ
_ArminS_
2026-04-14 14:56:12
(1 month ago)
WEB-Scan 25087:80 detected 2026.04.14 16:56:12
blocked until 2026.06.03 09:58:59
Port Scan
πΊπΈ
myagent.site
2026-04-14 11:51:54
(1 month ago)
Blocking for trying to access an exploit file: /wp-config-sample.php
Hacking
π«π·
dynamix
2026-04-10 16:48:05
(1 month ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-09 15:27:59
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 212.30.37.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 212.30.37.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 11:27:51.938156 2026] [security2:error] [pid 4129222:tid 4129222] [client 212.30.37.39:34801] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||triangleanchor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "triangleanchor.com"] [uri "/images/stories/themes.php"] [unique_id "adfFd5DqtoD4mjhakOZauQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-04-09 15:20:27
(1 month ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-09 12:45:50
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 212.30.37.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 212.30.37.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 08:45:21.342642 2026] [security2:error] [pid 3689797:tid 3689797] [client 212.30.37.39:27091] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||ashwoodsecurity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "ashwoodsecurity.com"] [uri "/images/stories/themes.php"] [unique_id "adefYa1OEQwQn6RcgYTeMwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack