๐ธ๐ช
vaia.cloud
2026-07-24 03:35:01
(3 hours ago)
crowdsecurity/http-wordpress-scan
Brute-Force
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-23 11:32:04
(19 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default:80 45.86.203.49 - - [18/Jul/2026:16:47:25 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default:80 45.86.203.49 - - [18/Jul/2026:16:47:25 +0300] "GET //zwso.php HTTP/1.1" 404 413 "-" "Go-http-client/1.1"
show less
Web App Attack
๐บ๐ธ
zwebvigil
2026-07-22 12:30:25
(1 day ago)
45.86.203.49 [22/Jul/2026:05:30:22 -0700] "GET /zwso.php HTTP/1.1" 404 196 "http://sip.<host>//zwso ...
show more
45.86.203.49 [22/Jul/2026:05:30:22 -0700] "GET /zwso.php HTTP/1.1" 404 196 "http://sip.<host>//zwso.php" port=61147 "Go-http-client/1.1" "-" "-" "sip.<host>" 804
45.86.203.49 [22/Jul/2026:05:30:22 -0700] "GET /wp-content/plugins/hellopress/wp_mna.php HTTP/1.1" 404 196 "http://sip.<host>/wp-content/plugins/hellopress/wp_mna.php" port=61147 "Go-http-client/1.1" "-" "-" "sip.<host>" 291
45.86.203.49 [22/Jul/2026:05:30:23 -0700] "GET /bolt.php HTTP/1.1" 404 196 "http://sip.<host>/bolt.php" port=61147 "Go-http-client/1.1" "-" "-" "sip.<host>" 745
45.86.203.49 [22/Jul/2026:05:30:23 -0700] "GET /cjfuns.php HTTP/1.1" 404 196 "http://sip.<host>/cjfuns.php" port=61147 "Go-http-client/1.1" "-" "-" "sip.<host>" 808
45.86.203.49 [22/Jul/2026:05:30:24 -0700] "GET /wp-admin/css/index.php HTTP/1.1" 404 196 "http://sip.<host>/wp-admin/css/index.php" port=61147 "Go-http-client/1.1" "-" "-" "sip.<host>" 396
45.86.203.49 [22/Jul/2026:
show less
Web App Attack
๐ฉ๐ช
findlab
2026-07-20 18:00:25
(3 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
Gabriel Camargo
2026-07-20 06:17:52
(4 days ago)
45.86.203.49 - - [20/Jul/2026:01:17:51 -0500] "GET /abcd.php HTTP/1.1" 301 178 "-" "Go-http-client/1 ...
show more
45.86.203.49 - - [20/Jul/2026:01:17:51 -0500] "GET /abcd.php HTTP/1.1" 301 178 "-" "Go-http-client/1.1"
45.86.203.49 - - [20/Jul/2026:01:17:52 -0500] "GET /shelp.php HTTP/1.1" 301 178 "-" "Go-http-client/1.1"
45.86.203.49 - - [20/Jul/2026:01:17:52 -0500] "GET /cord.php HTTP/1.1" 301 178 "-" "Go-http-client/1.1"
...
show less
Brute-Force
SSH
๐ซ๐ท
mail.avx.gr
2026-07-18 13:47:25
(5 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default:80 45.86.203.49 - - [18/Jul/2026:16:47:25 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default:80 45.86.203.49 - - [18/Jul/2026:16:47:25 +0300] "GET //zwso.php HTTP/1.1" 404 413 "-" "Go-http-client/1.1"
show less
Web App Attack
๐ต๐ฑ
sefinek.net
2026-07-18 08:26:27
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /cjfuns.php | UA: Go-http-client/1.1 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
maxpower
2026-06-12 07:18:30
(1 month ago)
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 45.86.203.49 (GB/United Kingdom/-): 1 in the ...
show more
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 45.86.203.49 (GB/United Kingdom/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 45.86.203.49 - - [12/Jun/2026:09:18:24 +0200] "GET /wp-content/plugins/file-upload-types/assets/css/403.php HTTP/1.1" 301 325 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" "45.86.203.49" host=villapardi.it
show less
Port Scan
๐ฉ๐ช
paissangroup
2026-06-12 03:07:56
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
cmbplf
2026-06-12 02:39:09
(1 month ago)
422 requests with url.path *config.php
Brute-Force
Bad Web Bot
๐ฌ๐ง
consul.to
2026-06-12 01:20:43
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฟ
Antinson
2026-05-19 19:44:17
(2 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-19 18:00:10
(2 months ago)
(mod_security) mod_security (id:240000) triggered by 45.86.203.49 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 45.86.203.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 14:00:00.285645 2026] [security2:error] [pid 15960:tid 15960] [client 45.86.203.49:50431] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||liverpoolfootballprogrammes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "liverpoolfootballprogrammes.com"] [uri "/images/stories/themes.php"] [unique_id "agylIKVn1Mbj4_EY8O0sCQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-18 04:34:30
(2 months ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-193)
Hacking
๐ซ๐ท
dynamix
2026-05-16 17:17:05
(2 months ago)
Multiple WAF Violations
Web App Attack