๐ซ๐ท
SpaceHost-Server
2026-09-16 22:19:32
(2 hours ago)
Brute-Force
Web App Attack
Anonymous
2026-09-16 10:31:50
(14 hours ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-09-15 22:19:11
(1 day ago)
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-09-15 17:27:13
(1 day ago)
2026/09/15 17:27:11 [error] 2447295#2447295: *1886502 access forbidden by rule, client: 34.145.245.2 ...
show more
2026/09/15 17:27:11 [error] 2447295#2447295: *1886502 access forbidden by rule, client: 34.145.245.27, server: finami.vn, request: "GET /.git/config HTTP/2.0", host: "finami-vn.com"
2026/09/15 17:27:12 [error] 2447295#2447295: *1886523 access forbidden by rule, client: 34.145.245.27, server: finami.vn, request: "GET /.env HTTP/2.0", host: "finami-vn.com"
2026/09/15 17:27:12 [error] 2447291#2447291: *1886536 access forbidden by rule, client: 34.145.245.27, server: finami.vn, request: "GET /.env.local HTTP/2.0", host: "finami-vn.com"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 11:13:37
(1 day ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 07:38:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.145.245.27 (27.245.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.245.27 (27.245.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:38:40.027446 2026] [security2:error] [pid 22810:tid 22810] [client 34.145.245.27:48882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigskyprints.com"] [uri "/.git/config"] [unique_id "aqj2AA06DRFnakO1dHqgKgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 15:05:38
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 34.145.245.27 (27.245.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.145.245.27 (27.245.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 11:05:35.221156 2026] [security2:error] [pid 8857:tid 8857] [client 34.145.245.27:64245] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.customhumanrobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.customhumanrobots.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoR0v1JIGmaiUbxKza733AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-18 14:57:14
(4 weeks ago)
Too many 404 requests [BY]
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-18 14:53:40
(4 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฟ
Antinson
2026-08-18 14:43:40
(4 weeks ago)
Scraping with a high error ratio and request rate
Bad Web Bot
Anonymous
2026-08-18 14:39:51
(4 weeks ago)
[redacted] 34.145.245.27 - - [18/Aug/2026:16:39:43 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" " ...
show more
[redacted] 34.145.245.27 - - [18/Aug/2026:16:39:43 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 34.145.245.27 - - [18/Aug/2026:16:39:44 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 34.145.245.27 - - [18/Aug/2026:16:39:45 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 34.145.245.27 - - [18/Aug/2026:16:39:46 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 34.145.245.27 - - [18/Aug/2026:16:39:47 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4
...
show less
Hacking
Web App Attack
๐ท๐ด
iulianh
2026-08-18 14:39:20
(4 weeks ago)
80,443
Brute-Force
SSH
๐ณ๐ฑ
ConsulHosting
2026-08-18 14:38:37
(4 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฉ๐ช
filstal.org
2026-08-18 14:38:01
(4 weeks ago)
WordPress login brute-force detected.
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-18 14:37:58
(4 weeks ago)
Try to access /xmlrpc.php?rsd
Web App Attack