๐ฉ๐ช
0x44
2026-09-03 08:05:20
(26 minutes ago)
TCP SYN Discovery - Flooding
DDoS Attack
๐ณ๐ฑ
Site.eu
2026-09-03 07:48:55
(43 minutes ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
Hary74656
2026-09-03 07:25:29
(1 hour ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
๐ฉ๐ช
updown.io
2026-09-03 07:24:48
(1 hour ago)
{"level":"info","ts":1788420287.8042178,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1788420287.8042178,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"2607:f298:5:114b::ff:e05a","remote_port":"49338","client_ip":"2607:f298:5:114b::ff:e05a","proto":"HTTP/1.1","method":"GET","host":"status.sharedenergymanager.com","uri":"/.env.save","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.sharedenergymanager.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000111443,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1788420287.806164,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"2607:f298:5:114b::ff:e05a","remote_port":"49278","client_ip":"2607:f298:5:114b::ff:e05a","proto":"HTTP/1.1","method":"GET","
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 06:42:27
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:42:21.139848 2026] [security2:error] [pid 29782:tid 29782] [client 2607:f298:5:114b::ff:e05a:58272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aiamur.com.aiamur.photo"] [uri "/.hg/store/00manifest.i"] [unique_id "apkWzSYND3_wgfTUtg1euwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-03 05:00:36
(3 hours ago)
WordPress config file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 04:47:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:47:51.708501 2026] [security2:error] [pid 27923:tid 27923] [client 2607:f298:5:114b::ff:e05a:34638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iconflgc.com"] [uri "/.env.orig"] [unique_id "apj794daNwrl7PG42-L-tQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-03 04:43:11
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-02 17:50:08
(14 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-02 17:46:56
(14 hours ago)
2607:f298:5:114b::ff:e05a - - [02/Sep/2026:19:46:51 +0200] "GET / HTTP/1.1" 200 59023 "-" "Mozilla/5 ...
show more
2607:f298:5:114b::ff:e05a - - [02/Sep/2026:19:46:51 +0200] "GET / HTTP/1.1" 200 59023 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:114b::ff:e05a - - [02/Sep/2026:19:46:52 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 4452 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:114b::ff:e05a - - [02/Sep/2026:19:46:52 +0200] "POST /wp-json/batch/v1 HTTP/1.1" 403 4451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:114b::ff:e05a - - [02/Sep/2026:19:46:53 +0200] "POST /index.php?rest_route=/batch/v1 HTTP/1.1" 403 4451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2607:f298:5:114b::ff:e05a - - [02/Sep/2026:19:46:53 +0200] "POST /index.php/wp-json/batch/v1 HTTP/1.1" 403 4451 "-" "
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 17:15:06
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:14:59.081800 2026] [security2:error] [pid 2371:tid 2371] [client 2607:f298:5:114b::ff:e05a:52790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abeltours.com"] [uri "/wp-config.php.bak"] [unique_id "aphZk965GjQihUxeAEWbGQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 16:43:22
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in ...
show more
(mod_security) mod_security (id:949110) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 12:43:14.360124 2026] [security2:error] [pid 20997:tid 20997] [client 2607:f298:5:114b::ff:e05a:37372] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.delcano.org"] [uri "/wp-config.php.bak"] [unique_id "aphSIuF-r5r8reUfRLjjogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-09-02 15:02:38
(17 hours ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-02 14:15:17
(18 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 13:56:08
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:5:114b::ff:e05a (xtreammax.lat): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:56:04.815790 2026] [security2:error] [pid 25489:tid 25569] [client 2607:f298:5:114b::ff:e05a:55190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koalacogs.com"] [uri "/wp-config.php.bak"] [unique_id "apgq9BjYxEGu4EllWjVrBgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack