🇫🇷
arsonist
2026-09-05 04:24:07
(1 day ago)
[fail2ban]
2026-09-05T04:24:07.241444+00:00 arson caddy[1890453]: {"level":"info","ts":1788582247.24 ...
show more
[fail2ban]
2026-09-05T04:24:07.241444+00:00 arson caddy[1890453]: {"level":"info","ts":1788582247.2414265,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"38.247.189.207","remote_port":"62157","client_ip":"38.247.189.207","proto":"HTTP/1.1","method":"GET","host":"cp.arson.gg","uri":"/wp-admin/admin-ajax.php","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"],"Accept":["*/*"],"Accept-Encoding":["gzip, deflate, zstd"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"cp.arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000092373,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"X-Content-Type-Options":["nosniff"],"X-Xss-Protection":["1; mode=block;"],"Content-Security-Policy":["frame-ancestors 'self'"],"X-Frame-Options":["D
...
show less
Bad Web Bot
Anonymous
2026-09-05 04:20:38
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇬🇧
venus.launch.bz
2026-09-05 04:03:28
(1 day ago)
(wpscan) WordPress probe detected from 38.247.189.207 (US/United States/-)
Hacking
🇳🇴
jad-abuse
2026-09-05 01:27:33
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 6 hits.
show less
Brute-Force
Web App Attack
🇫🇷
ELYAZ
2026-09-04 01:27:16
(2 days ago)
(y3) Failed access -byebye- from 38.247.189.207 (US/United States/-): (CF_ENABLE)
Hacking
🇫🇮
Rauno Asp
2026-09-03 22:58:13
(2 days ago)
Malicious scanning/exploit attempt detected on elbasanapartments.al (fail2ban jail: webattack)
Web App Attack
🇳🇱
ipoac.nl
2026-09-02 05:10:55
(4 days ago)
ipoac.nl:80 38.247.189.207 - - [02/Sep/2026:07:10:54 +0200] - "GET /wp-admin/admin-ajax.php?action=w ...
show more
ipoac.nl:80 38.247.189.207 - - [02/Sep/2026:07:10:54 +0200] - "GET /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect= HTTP/1.1" 302 1011 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-02 04:56:37
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:56:31.038421 2026] [security2:error] [pid 17138:tid 17138] [client 38.247.189.207:61314] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.stoughtonpipeandwelding.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.stoughtonpipeandwelding.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apesdI4j-51z4TI_euzWkwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 04:34:57
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:34:49.955431 2026] [security2:error] [pid 18392:tid 18392] [client 38.247.189.207:50562] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||4115thewestford.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "4115thewestford.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apenUImgNzyWt76v2ZPrWgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 04:07:26
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:07:18.968112 2026] [security2:error] [pid 13549:tid 13549] [client 38.247.189.207:59980] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.avaliantlife.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apeg8pU1zTVHVfc-zIHsvgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 03:48:19
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:48:11.609076 2026] [security2:error] [pid 6787:tid 6787] [client 38.247.189.207:65023] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6649"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||advantagept.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "advantagept.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apeceLYYjH32bcdFKXn6iwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
rellik
2026-09-02 03:32:00
(4 days ago)
Scanning Critical File
Hacking
Web App Attack
🇺🇸
webgobe
2026-09-02 03:29:34
(4 days ago)
lee-7 : Trying access unauthorized files/dir=>/wp-admin/admin-ajax.php?action=wdpsso_step1&redir ...
show more
lee-7 : Trying access unauthorized files/dir=>/wp-admin/admin-ajax.php?action=wdpsso_step1&redirect=
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-02 03:26:59
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:26:53.739023 2026] [security2:error] [pid 31986:tid 31986] [client 38.247.189.207:63032] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||adona.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "adona.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apeXfJJdRvL-dbz6pn-GDQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 03:06:09
(4 days ago)
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:243420) triggered by 38.247.189.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:06:05.636346 2026] [security2:error] [pid 22050:tid 22056] [client 38.247.189.207:59935] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||thecraftsycat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thecraftsycat.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apeSmwQ-547i7CH1REz-xAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack