π°π·
enp0s1
2026-02-27 04:13:31
(6 months ago)
Auto-reported by Fail2Ban (UFW Block, Port Scan)
Port Scan
π³π±
jjnxpct
2026-02-24 04:47:59
(6 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /setup-config.php (Rule ID: 930130) - Restricted File Access Attempt
show less
Web App Attack
Hacking
π³π±
Site.eu
2026-02-24 04:10:46
(6 months ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-02-24 04:05:24
(6 months ago)
Blocked: Reason='Vulnerability probing β PHP scan detected (33/60 min)'; Requests=33
Port Scan
π©πͺ
ps-center
2026-02-24 02:11:17
(6 months ago)
C1: Web Attack GET /wp-includes/css/dist/
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-02-24 01:30:31
(6 months ago)
[redacted] 45.67.97.43 - - [24/Feb/2026:02:30:23 +0100] "GET /wp-admin/js/widgets/ HTTP/1.1" 404 236 ...
show more
[redacted] 45.67.97.43 - - [24/Feb/2026:02:30:23 +0100] "GET /wp-admin/js/widgets/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36"
[redacted] 45.67.97.43 - - [24/Feb/2026:02:30:23 +0100] "GET /wp-content/plugins/wp-file-manager/admin/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
[redacted] 45.67.97.43 - - [24/Feb/2026:02:30:24 +0100] "GET /wp-admin/js/widget/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36"
[redacted] 45.67.97.43 - - [24/Feb/2026:02:30:26 +0100] "GET /wp-admin/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
[redacted] 45.67.97.43 - - [24/Feb/2026:02:30:26 +0100] "GET /wordpress/wp-admin/includes HTTP/1.1" 404 2
...
show less
Hacking
Web App Attack
πΊπΈ
mnsf
2026-02-24 01:05:17
(6 months ago)
Request Overload (108)
Brute-Force
Web App Attack
π«π·
dynamix
2026-02-23 23:48:33
(6 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
myagent.site
2026-02-23 23:13:08
(6 months ago)
Blocking for trying to access an exploit file: /manager.php
Hacking
π³πΏ
Antinson
2026-02-23 17:42:25
(6 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
Anonymous
2026-02-23 17:19:13
(6 months ago)
[redacted] 45.67.97.43 - - [23/Feb/2026:18:19:03 +0100] "GET /admin/function.php HTTP/1.1" 404 236 " ...
show more
[redacted] 45.67.97.43 - - [23/Feb/2026:18:19:03 +0100] "GET /admin/function.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36"
[redacted] 45.67.97.43 - - [23/Feb/2026:18:19:04 +0100] "GET /wp-includes/js/crop/admin.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36"
[redacted] 45.67.97.43 - - [23/Feb/2026:18:19:05 +0100] "GET /wp-includes/PHPMailer/admin.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
[redacted] 45.67.97.43 - - [23/Feb/2026:18:19:08 +0100] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
[redacted] 45.67.97.43 - - [23/Feb/2026:
...
show less
Hacking
Web App Attack
πΊπΈ
rsa
2026-02-23 16:52:00
(6 months ago)
GET /wp-content/themes/twentytwentythree/patterns/index.php HTTp
Brute-Force
Web App Attack
Hacking
π¨π
Origon
2026-02-23 14:57:25
(6 months ago)
http-backdoors-attempts - IP: 45.67.97.43 - time="2026-02-23T15:57:25+01:00" level=info msg="(555f6 ...
show more
http-backdoors-attempts - IP: 45.67.97.43 - time="2026-02-23T15:57:25+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-backdoors-attempts by ip 45.67.97.43 (KR/40676) : 4h ban on Ip 45.67.97.43" module=db
show less
Web App Attack
π¬π§
consul.to
2026-02-23 12:35:43
(6 months ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-23 10:11:42
(6 months ago)
(mod_security) mod_security (id:240000) triggered by 45.67.97.43 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 45.67.97.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 05:11:36.885850 2026] [security2:error] [pid 12026:tid 12026] [client 45.67.97.43:45829] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||emgeorge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "emgeorge.com"] [uri "/images/stories/themes.php"] [unique_id "aZwn2F-vigumm9lch1eZOwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack