๐ณ๐ฑ
Alt255
2026-10-01 05:29:14
(42 minutes ago)
[cb-09al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[cb-09al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 45.3.52.112 - - [01/Oct/2026:07:21:27 +0200] "POST /wp-login.php HTTP/1.1" 301 4613 "-" "Goosee-Audit/1.0 (+internal-security-audit)"
45.3.52.112 - - [01/Oct/2026:07:23:32 +0200] "POST /wp-login.php HTTP/1.1" 301 4614 "-" "Goosee-Audit/1.0 (+internal-security-audit)"
45.3.52.112 - - [01/Oct/2026:07:24:15 +0200] "POST /wp-login.php HTTP/1.1" 301 4613 "-" "Goosee-Audit/1.0 (+internal-security-audit)"
45.3.52.112 - - [01/Oct/2026:07:29:10 +0200] "POST /wp-login.php HTTP/1.1" 301 4613 "-" "Goosee-Audit/1.0 (+internal-security-audit)"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-20 23:14:26
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ซ๐ท
Sklurk
2026-08-05 00:41:12
(1 month ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-08 01:32:10
(2 months ago)
Web App Attack
Web App Attack
๐ช๐ธ
NullBlue
2026-07-03 16:40:29
(2 months ago)
Docker API exploitation attempt. Captured by NullBlue67 honeypot.
Hacking
Exploited Host
Web App Attack
๐ช๐ธ
masterguru
2026-03-27 02:25:46
(6 months ago)
. Matched phrase "/.env" at REQUEST_URI. (210492-123)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-03-02 22:59:09
(6 months ago)
Auto-ban: >3000 req/min op 2026-03-02
Web App Attack
SSH
Hacking
๐ฉ๐ช
KPS
2026-02-28 16:21:50
(7 months ago)
PortscanM
Port Scan
๐ฉ๐ฐ
TransAdvice-Abuse
2025-12-26 10:58:40
(9 months ago)
IRC SPAM/Flood
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 22:14:13
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:14:06.118998 2025] [security2:error] [pid 5388:tid 5399] [client 45.3.52.112:22537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proracersecrets.com"] [uri "/.svn/wc.db"] [unique_id "aS9kroblRFgPexd0O-znZAAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 20:08:01
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 15:07:56.358493 2025] [security2:error] [pid 27085:tid 27105] [client 45.3.52.112:34995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "titanweb.com"] [uri "/.svn/wc.db"] [unique_id "aS9HHE3nwAtP2XkZXXJ1hAAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 13:43:52
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 08:43:48.151737 2025] [security2:error] [pid 28817:tid 28817] [client 45.3.52.112:17573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rachelfia.com"] [uri "/.env"] [unique_id "aS7tFJCO0ZFbTYr8P3oILgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 07:06:43
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:06:38.170879 2025] [security2:error] [pid 5992:tid 5992] [client 45.3.52.112:16495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "closedfortheseason.com"] [uri "/.svn/wc.db"] [unique_id "aS6P_u5DqOVmCa4hj6VIvwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:14:22
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:14:17.458741 2025] [security2:error] [pid 32252:tid 32252] [client 45.3.52.112:29075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulshorrock.com"] [uri "/.env"] [unique_id "aS51qQLdvnwu_whiZwfxtAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:24:46
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.52.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:24:04.810583 2025] [security2:error] [pid 18636:tid 18636] [client 45.3.52.112:10029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sittser.com"] [uri "/.svn/wc.db"] [unique_id "aSVLhIbs1Gni50Q-tQnKWAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack