๐ฏ๐ต
S.O.B.A. Dev.
2026-09-23 05:48:32
(5 days ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-23 03:27:31
(5 days ago)
Excessive HTTP request rate
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-23 00:50:04
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-23 00:21:24
(5 days ago)
2a02:c207:2318:6436::1 - - [23/Sep/2026:02:21:20 +0200] "POST / HTTP/1.1" 207 5257 "-" "Mozilla/5.0 ...
show more
2a02:c207:2318:6436::1 - - [23/Sep/2026:02:21:20 +0200] "POST / HTTP/1.1" 207 5257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
[site]:443 2a02:c207:2318:6436::1 - - [22/Sep/2026:12:50:11 +0200] "GET / HTTP/1.1" 503 4533 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:c207:2318:6436::1 - - [22/Sep/2026:17:25:44 +0200] "GET /api/session/properties HTTP/1.1" 301 596 "-" "metabase-cve-2026-72898-detect/1.0 (benign detection probes only)"
2a02:c207:2318:6436::1 - - [22/Sep/2026:17:25:44 +0200] "GET /api/session/properties HTTP/1.1" 404 30747 "-" "metabase-cve-2026-72898-detect/1.0 (benign detection probes only)"
2a02:c207:2318:6436::1 - - [22/Sep/2026:17:25:49 +0200] "GET /api/session/properties HTTP/1.1" 404 30718 "http://[site]/api/session/properties" "metabase-cve-2026-72898-detect/1.0 (benign detection probes only)"
2a02:c207:2318:6436::1 -
show less
Web App Attack
Hacking
๐บ๐ธ
Major Hostility
2026-09-22 23:54:15
(5 days ago)
"GET /api/session/properties HTTP/1.1" 404
"GET /api/session/properties HTTP/1.1" 404
Web App Attack
๐ณ๐ฑ
ismailk
2026-09-22 22:31:03
(5 days ago)
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=FR puan=97 nginx=0 wf=0 cf=6 hiz= ...
show more
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=FR puan=97 nginx=0 wf=0 cf=6 hiz=2 404cesit=0. Blocked by adaptive firewall.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 20:43:59
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2318:6436::1 (vmi3186436.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2318:6436::1 (vmi3186436.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:43:53.718536 2026] [security2:error] [pid 29453:tid 29453] [client 2a02:c207:2318:6436::1:45934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ultratecnologia.com.mx"] [uri "/wp-config.php~"] [unique_id "arLoiR3gkhLg8Dq9O0PTnwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-09-22 14:32:55
(5 days ago)
$f2bV_matches
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 14:14:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2318:6436::1 (vmi3186436.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2318:6436::1 (vmi3186436.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:13:53.969509 2026] [security2:error] [pid 10729:tid 10729] [client 2a02:c207:2318:6436::1:39442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staben.com"] [uri "/wp-config.php.bak"] [unique_id "arKNIXI-wmRR2EW1vMDkBAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-22 13:09:38
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 10:48:24
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2318:6436::1 (vmi3186436.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2318:6436::1 (vmi3186436.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:48:19.399761 2026] [security2:error] [pid 29569:tid 29589] [client 2a02:c207:2318:6436::1:38950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.councilofforeignministers.aafm.us"] [uri "/wp-config.php.bak"] [unique_id "arJc88hqftFZTPksRplNIwAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 10:40:38
(5 days ago)
[Tue Sep 22 10:40:27.479254 2026] [authz_core:error] [pid 175440:tid 175474] [client 2a02:c207:2318: ...
show more
[Tue Sep 22 10:40:27.479254 2026] [authz_core:error] [pid 175440:tid 175474] [client 2a02:c207:2318:6436::1:50030] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/api
[Tue Sep 22 10:40:27.490597 2026] [authz_core:error] [pid 177630:tid 177660] [client 2a02:c207:2318:6436::1:37954] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/api
[Tue Sep 22 10:40:32.287621 2026] [authz_core:error] [pid 174505:tid 174578] [client 2a02:c207:2318:6436::1:37956] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/api
[Tue Sep 22 10:40:32.499699 2026] [authz_core:error] [pid 175440:tid 175479] [client 2a02:c207:2318:6436::1:37960] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/api
[Tue Sep 22 10:40:37.810137 2026] [authz_core:error] [pid 177630:tid 177659] [client 2a02:c207:2318:6436::1:38160] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/api
...
show less
Brute-Force
๐ฉ๐ช
IVski.com
2026-09-22 08:37:36
(6 days ago)
IVski WAF | Metabase CVE-2026-72898 probe - querying /api/session/properties
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 06:57:36
(6 days ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:c207:2318:6436::1 - - [22/Sep/2026:08:57:23 +0200] "GET /wp-config.php.old HTTP/1.1" 404 37017 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 03:12:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2318:6436::1 (vmi3186436.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2318:6436::1 (vmi3186436.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 23:12:50.053114 2026] [security2:error] [pid 15341:tid 15341] [client 2a02:c207:2318:6436::1:36228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tcit.org"] [uri "/wp-config.php~"] [unique_id "arHyMqJVBG_IvzRbxfoH5AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack