π©πͺ
LRob
2026-08-15 03:31:34
(2 weeks ago)
WordPress login brute-force | req: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) App ...
show more
WordPress login brute-force | req: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
show less
Brute-Force
Web App Attack
π«π·
pm33
2026-08-14 17:47:26
(2 weeks ago)
Wordpress login attempts
Brute-Force
π©πͺ
pltcldvlpr
2026-08-13 12:06:58
(2 weeks ago)
CMS/framework probe: 2a02:c207:2295:3236::1 - - [13/Aug/2026:14:06:57 +0200] "GET /wp-json/ HTTP/2.0 ...
show more
CMS/framework probe: 2a02:c207:2295:3236::1 - - [13/Aug/2026:14:06:57 +0200] "GET /wp-json/ HTTP/2.0" 404 94423 "-" "wp2shell" asn=51167 org="Contabo GmbH" country=DE
...
show less
Web App Attack
Anonymous
2026-08-09 04:33:18
(3 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π³π±
homeshowdomain.nl
2026-08-07 21:59:49
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-06.
show less
Web App Attack
SSH
Hacking
πΊπΈ
interbiznw.com
2026-08-07 14:12:14
(3 weeks ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-07 14:00:36
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserve ...
show more
(mod_security) mod_security (id:949110) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 10:00:29.263878 2026] [security2:error] [pid 2095179:tid 2095179] [client 2a02:c207:2295:3236::1:35074] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "danchujkoassoc.com"] [uri "/.env"] [unique_id "anXk_UhvHE7eK5OjXjg9CgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-07 11:51:45
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserve ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:51:38.833147 2026] [security2:error] [pid 18730:tid 18730] [client 2a02:c207:2295:3236::1:37748] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dadhania.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dadhania.net"] [uri "/"] [unique_id "anXGyj9T1CsUBZUlUate4AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
hidemail.app
2026-08-07 10:01:09
(3 weeks ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-07 08:55:46
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserve ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:55:40.715525 2026] [security2:error] [pid 1665963:tid 1665963] [client 2a02:c207:2295:3236::1:39350] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||galvez.cc|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "galvez.cc"] [uri "/"] [unique_id "anWdjOxPfpHu20Ptzg0GqgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-07 06:45:27
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserve ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 02:45:20.230805 2026] [security2:error] [pid 2588536:tid 2588536] [client 2a02:c207:2295:3236::1:49878] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||chickiesbeef.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "chickiesbeef.com"] [uri "/"] [unique_id "anV_AHde2GB_CjVQX29IJQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-08-07 05:35:27
(3 weeks ago)
Try to access /.env
Web App Attack
π©πͺ
gadix
2026-08-07 04:54:01
(3 weeks ago)
[07/Aug/2026:06:54:00.354491 +0200] anVk6FtactdM9A49jTNqKQAAAAA 2a02:c207:2295:3236::1 45784 127.0.0 ...
show more
[07/Aug/2026:06:54:00.354491 +0200] anVk6FtactdM9A49jTNqKQAAAAA 2a02:c207:2295:3236::1 45784 127.0.0.1 7081
[07/Aug/2026:06:54:01.000340 +0200] anVk6G7xwXf3bMUc1BOYmgAAAAU 2a02:c207:2295:3236::1 45792 127.0.0.1 7081
[07/Aug/2026:06:54:01.059896 +0200] anVk6T_QO364qUoNtC8hxgAAAAM 2a02:c207:2295:3236::1 45800 127.0.0.1 7081
...
show less
Web App Attack
π΅π±
Niko's Stuff
2026-08-07 04:44:34
(3 weeks ago)
Triggered crowdsecurity/http-sensitive-files. More information at: https://app.crowdsec.net/cti/2a02 ...
show more
Triggered crowdsecurity/http-sensitive-files. More information at: https://app.crowdsec.net/cti/2a02:c207:2295:3236::1
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-07 04:38:27
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserve ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2295:3236::1 (vmi2953236.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 00:38:21.048482 2026] [security2:error] [pid 21775:tid 21775] [client 2a02:c207:2295:3236::1:44032] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bikelatch.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bikelatch.com"] [uri "/"] [unique_id "anVhPaXkHK5ByhhAIA2atAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack