🇫🇷
bazter.pro
2026-09-05 01:06:29
(22 hours ago)
Auto-Ban [2026-09-05 04:06:29]: CRITICAL: High-score datacenter (58% AbuseIPDB, Google LLC); DC: Goo ...
show more
Auto-Ban [2026-09-05 04:06:29]: CRITICAL: High-score datacenter (58% AbuseIPDB, Google LLC); DC: Google LLC [Paths: 7] | Details: 404 errors (6): /backup/, /old/, /wp/, /blog/, /wordpress/, /new/ | Other paths: /
show less
Web App Attack
🇷🇸
Smel
2026-09-05 00:22:05
(23 hours ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
🇬🇷
setupgr
2026-09-04 23:35:37
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 34.148.197.168 (US/United States/South Caroli ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.148.197.168 (US/United States/South Carolina/North Charleston/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Sep 05 02:35:32.427357 2026] [security2:error] [pid 3130:tid 3314] [client 34.148.197.168:43116] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 168.197.148.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "mail.cpanagiotou.gr"] [uri "/wordpress/"] [unique_id "aptVxD7Zg2B0kuOLGX5_cAAAAhY"]
show less
Port Scan
🇺🇸
rsa
2026-09-04 23:26:00
(1 day ago)
HEAD /new/ HTTP/1.1
DDoS Attack
Exploited Host
Web App Attack
🇬🇧
abivia
2026-09-04 23:13:09
(1 day ago)
Abivia WAF trigger: Rule install-fishing: Looking for old installs. uri: /old/
Hacking
Web App Attack
🇺🇸
webgobe
2026-09-04 23:10:01
(1 day ago)
mae-7 : Trying access unauthorized files/dir=>/wordpress/
Hacking
🇫🇷
conseilgouz
2026-09-04 23:02:07
(1 day ago)
mae-7 : Trying access unauthorized files/dir=>/wordpress/
Hacking
🇦🇺
aranguren.org
2026-09-04 22:19:59
(1 day ago)
34.148.197.168 - - [05/Sep/2026:08:19:56 +1000] "HEAD /wordpress/ HTTP/2.0" 403 998 "http://mail.lui ...
show more
34.148.197.168 - - [05/Sep/2026:08:19:56 +1000] "HEAD /wordpress/ HTTP/2.0" 403 998 "http://mail.luisaranguren.com/wordpress/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1"
34.148.197.168 - - [05/Sep/2026:08:19:56 +1000] "HEAD /old/ HTTP/2.0" 403 998 "http://mail.luisaranguren.com/old/" "Mozilla/5.0 (Linux; Android 12; TECNO CK6n) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.50 Mobile Safari/537.36"
34.148.197.168 - - [05/Sep/2026:08:19:57 +1000] "HEAD /blog/ HTTP/2.0" 403 998 "http://mail.luisaranguren.com/blog/" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edg/128.0.2790.25 Chrome/128.0.6540.22 Safari/537.36"
34.148.197.168 - - [05/Sep/2026:08:19:58 +1000] "HEAD /backup/ HTTP/2.0" 403 998 "http://mail.luisaranguren.com/backup/" "Mozilla/5.0 (Linux; Android 14; OnePlus 12) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.102 Mobile Safari
...
show less
Bad Web Bot
🇬🇷
setupgr
2026-09-04 21:52:03
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 34.148.197.168 (US/United States/South Caroli ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.148.197.168 (US/United States/South Carolina/North Charleston/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Sep 05 00:51:59.100345 2026] [security2:error] [pid 3238:tid 3359] [client 34.148.197.168:39852] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 168.197.148.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "mail.endoscope.center"] [uri "/wordpress/"] [unique_id "aps9f7EkBqlZbSc_rTb0bwAAAoY"]
show less
Port Scan
🇺🇸
dot.mg
2026-09-04 21:23:22
(1 day ago)
Bruteforce
Bad Web Bot
🇨🇦
polycoda
2026-09-04 20:59:16
(1 day ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - 📂 Directory Listings (Decay-Based) - ↪️ Exces ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - 📂 Directory Listings (Decay-Based) - ↪️ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
🇬🇷
setupgr
2026-09-04 20:23:14
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 34.148.197.168 (US/United States/South Caroli ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.148.197.168 (US/United States/South Carolina/North Charleston/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 04 23:23:10.509152 2026] [security2:error] [pid 3626:tid 3732] [client 34.148.197.168:49708] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 168.197.148.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "mail.doityourself.gr"] [uri "/wordpress/"] [unique_id "apsorredDLhy7mJe8DNCSwAABEI"]
show less
Port Scan