๐ณ๐ฑ
oisecnet
2026-06-10 21:01:19
(1 day ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-06-10. 227 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-06-10. 227 requests from this IP.
show less
Brute-Force
Web App Attack
SSH
๐ฆ๐น
neo72
2026-06-10 12:46:22
(2 days ago)
Detected malicious activity - bulk block
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-10 11:05:35
(2 days ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-10 11:04:25
(2 days ago)
24.927 requests in 1 hour (3mos1w2d)
Brute-Force
Bad Web Bot
๐ฉ๐ช
iNetWorker
2026-06-10 10:51:00
(2 days ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ช
webanyone
2026-06-10 10:45:27
(2 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-06-10 10:42:21
(2 days ago)
10 attempts against mh-misc-ban on choy
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-10 10:42:17
(2 days ago)
Try to access /xmlrpc.php?rsd
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 10:41:17
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 34.148.94.211 (211.94.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.148.94.211 (211.94.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 06:41:12.259488 2026] [security2:error] [pid 15657:tid 15657] [client 34.148.94.211:55724] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.godcanuseyou.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.godcanuseyou.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aik_SGi0j89o0lDXZqoNWAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-06-10 10:33:12
(2 days ago)
AetherFox VoidGuard detected: [Wed Jun 10 10:33:11.219791 2026] [authz_core:error] [pid 4118972:tid ...
show more
AetherFox VoidGuard detected: [Wed Jun 10 10:33:11.219791 2026] [authz_core:error] [pid 4118972:tid 4118985] [client 34.148.94.211:49770] AH01630: client denied by server configuration: proxy:http://[MASKED]/wp-includes/ID3/license.txt
[Wed Jun 10 10:33:11.220064 2026] [authz_core:error] [pid 4118972:tid 4118985] [client 34.148.94.211:49770] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Wed Jun 10 10:33:11.360911 2026] [authz_core:error] [pid 4118972:tid 4118981] [client 34.148.94.211:49770] AH01630: client denied by server configuration: proxy:http://[MASKED]/feed/
[Wed Jun 10 10:33:11.361339 2026] [authz_core:error] [pid 4118972:tid 4118981] [client 34.148.94.211:49770] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Wed Jun 10 10:33:11.465065 2026] [authz_core:error] [pid 4118972:tid 4118978] [client 34.148.94.211:49770] AH01630: client denied by server configuration: proxy:http://5.75.
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-10 10:30:32
(2 days ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
Anonymous
2026-06-10 10:21:39
(2 days ago)
[redacted] 34.148.94.211 - - [10/Jun/2026:12:21:32 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" " ...
show more
[redacted] 34.148.94.211 - - [10/Jun/2026:12:21:32 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 34.148.94.211 - - [10/Jun/2026:12:21:32 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 34.148.94.211 - - [10/Jun/2026:12:21:33 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 34.148.94.211 - - [10/Jun/2026:12:21:34 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 34.148.94.211 - - [10/Jun/
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 10:19:25
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 34.148.94.211 (211.94.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.148.94.211 (211.94.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 06:19:18.118769 2026] [security2:error] [pid 7093:tid 7093] [client 34.148.94.211:50745] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.glendaleheritage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.glendaleheritage.org"] [uri "/wp-includes/id3/license.txt/blog/wp-json/wp/v2/users/"] [unique_id "aik6JuYqDjwF_0812rkBJAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-10 10:18:25
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
sthoyer.de
2026-06-10 10:10:40
(2 days ago)
34.148.94.211 - - [10/Jun/2026:12:10:38 +0200] "GET /users/sign_in/feed/ HTTP/1.1" 302 102 "-" "Mozi ...
show more
34.148.94.211 - - [10/Jun/2026:12:10:38 +0200] "GET /users/sign_in/feed/ HTTP/1.1" 302 102 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.148.94.211 - - [10/Jun/2026:12:10:38 +0200] "GET /users/sign_in/xmlrpc.php?rsd HTTP/1.1" 302 102 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.148.94.211 - - [10/Jun/2026:12:10:38 +0200] "GET /users/sign_in/blog/wp-includes/wlwmanifest.xml HTTP/1.1" 302 102 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.148.94.211 - - [10/Jun/2026:12:10:39 +0200] "GET /users/sign_in/web/wp-includes/wlwmanifest.xml HTTP/1.1" 302 102 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.148.94.211 - - [10/Jun/2026:12:10:39 +0200] "GET /users/sign_in/wordpress/wp-includes/w
...
show less
Brute-Force