🇮🇹
CoreTech srl
2026-09-04 17:13:56
(22 hours ago)
cloudlinux2 fail2ban: 2026-09-04 19:08:49,940 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 19:08:49,940 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 90.241.189.228 - 2026-09-04 19:08:49cloudlinux2 fail2ban: 2026-09-04 19:09:30,331 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Ban 175.107.247.13cloudlinux2 fail2ban: 2026-09-04 19:09:30,337 fail2ban.filter [1594]: INFO [recidive] Found 175.107.247.13 - 2026-09-04 19:09:30cloudlinux2 fail2ban: 2026-09-04 19:09:29,998 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 175.107.247.13 - 2026-09-04 19:09:29cloudlinux2 fail2ban: 2026-09-04 19:09:55,281 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.131.193.36 - 2026-09-04 19:09:54cloudlinux2 fail2ban: 2026-09-04 19:10:09,588 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.176.41.205cloudlinux2 fail2ban: 2026-09-04 19:10:13,339 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.81.53.46 - 2026-09-04 19:10:13cloudlinux2 fail2ban: 2026-09-04 19:10:11,721 fail
show less
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 10:29:41
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇩🇪
LRob
2026-09-03 12:35:08
(2 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: / | query: author=1 (+3 more) | 2026-09-03 12:35 UTC
show less
Hacking
Web App Attack
🇩🇪
LRob
2026-09-01 23:23:49
(3 days ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-01 23:23 UTC
Brute-Force
Web App Attack
🇫🇷
tecnicorioja
2026-09-01 22:00:53
(3 days ago)
wp-login attack [01/Sep/2026:14:37:49
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-08-28 23:13:15
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇩🇪
LRob
2026-08-28 00:09:19
(1 week ago)
WordPress login brute-force | path: /wp-login.php | 2026-08-28 00:09 UTC
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-08-26 17:52:22
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.tech | URI: /wp-login.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-08-26 10:56:03
(1 week ago)
Wordfence waf block on registrymatters
Web App Attack
🇧🇪
brechtr
2026-08-26 08:53:39
(1 week ago)
[Press84-BanHammer] bad username — Sourced from: brechtryckaert.com — Request: POST /wp-login.php
Brute-Force
🇺🇸
TPI-Abuse
2026-08-20 13:34:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 09:34:09.417027 2026] [security2:error] [pid 3166:tid 3166] [client 45.131.193.36:21807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.204"] [uri "/.env"] [unique_id "aocCUfh2vknrJ-cwudPWKwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 12:03:28
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 08:03:18.327147 2026] [security2:error] [pid 7430:tid 7430] [client 45.131.193.36:62329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.172"] [uri "/backend/.env"] [unique_id "aobtBv-6VypvKgS21p4A1gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 11:18:32
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 07:18:15.912947 2026] [security2:error] [pid 13388:tid 13388] [client 45.131.193.36:44127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.101"] [uri "/wp-admin/.env"] [unique_id "aobid8IRjFxvOeGFFhUKlAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 10:04:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 06:04:03.656994 2026] [security2:error] [pid 17026:tid 17026] [client 45.131.193.36:59601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.197"] [uri "/audio/.env"] [unique_id "aobREzpFJokDyc5a6NMkCgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 08:39:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.193.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 04:39:19.058079 2026] [security2:error] [pid 3992:tid 3992] [client 45.131.193.36:25165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.16"] [uri "/base/.env"] [unique_id "aoa9N-c0cDgtH_kKV-ut5QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack