๐ฎ๐ช
AutosOnShow
2026-09-25 13:57:04
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-25 13:56:12.072 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-25 11:00:09
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-25 10:59:15.590 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-24 13:28:04
(2 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-24 13:27:46.404 |
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-14 11:48:56
(1 week ago)
cloudlinux2 fail2ban: 2026-09-14 13:43:58,147 fail2ban.filter [1908]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-14 13:43:58,147 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 90.140.168.216 - 2026-09-14 13:43:57cloudlinux2 fail2ban: 2026-09-14 13:44:19,638 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 192.140.151.58 - 2026-09-14 13:44:19cloudlinux2 fail2ban: 2026-09-14 13:45:23,846 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 192.140.151.58 - 2026-09-14 13:45:23cloudlinux2 fail2ban: 2026-09-14 13:45:32,116 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Unban 119.155.206.39cloudlinux2 fail2ban: 2026-09-14 13:45:34,626 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 192.140.151.58 - 2026-09-14 13:45:34cloudlinux2 fail2ban: 2026-09-14 13:45:34,733 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Ban 192.140.151.58cloudlinux2 fail2ban: 2026-09-14 13:45:34,826 fail2ban.filter [1908]: INFO [recidive] Found 192.140.151.58 - 2026-09-14 13:45:34cloudlinux2 fail2ban: 2026-09-14 13:47:44,104
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-25 16:33:57
(1 month ago)
cloudlinux2 fail2ban: 2026-08-25 18:28:49,674 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-25 18:28:49,674 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.67.134 - 2026-08-25 18:28:49cloudlinux2 fail2ban: 2026-08-25 18:28:50,567 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.23.237 - 2026-08-25 18:28:50cloudlinux2 fail2ban: 2026-08-25 18:28:54,773 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.2.210 - 2026-08-25 18:28:54cloudlinux2 fail2ban: 2026-08-25 18:28:55,715 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.89.105 - 2026-08-25 18:28:55cloudlinux2 fail2ban: 2026-08-25 18:28:52,035 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.7.201 - 2026-08-25 18:28:51cloudlinux2 fail2ban: 2026-08-25 18:28:53,388 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.81.39 - 2026-08-25 18:28:53cloudlinux2 fail2ban: 2026-08-25 18:29:09,156 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 146.19.140.185 - 2026-08-25 18:29:08cloudl
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-25 09:25:24
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 23:25:26
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 217.181.81.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 217.181.81.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 19:25:19.361769 2026] [security2:error] [pid 1092014:tid 1092014] [client 217.181.81.39:58470] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||salernospizza.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "salernospizza.com"] [uri "/wp-login.php"] [unique_id "anuvX2Ia26FkVPsJ31coGQAAAAM"], referer: https://salernospizza.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Oakley
2026-07-08 04:07:39
(2 months ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐ฎ๐ฉ
bps-statistics
2026-06-17 02:47:27
(3 months ago)
WP Login Scan Activities: "2026-06-17T09:47:27.685+07:00" "/wp-login.php" "217.181.81.39" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-06-17T09:47:27.685+07:00" "/wp-login.php" "217.181.81.39" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
show less
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-06-12 11:48:03
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -48.79 (Bad < -10 / Very Bad < -20 / ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -48.79 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-03 14:16:09
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 217.181.81.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 217.181.81.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 09:16:01.149044 2026] [security2:error] [pid 3024:tid 3024] [client 217.181.81.39:26556] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dwightbrown.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dwightbrown.com"] [uri "/wp-login.php"] [unique_id "aabtIf06xRLgAWw9ktOy0AAAABc"], referer: https://dwightbrown.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack