๐ณ๐ฑ
Tsumugi Kotobuki
2026-10-02 11:25:17
(2 days ago)
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 52 | Len: 60B | Win: ...
show more
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 52 | Len: 60B | Win: 64240(1) | F2B/ufw-honeypot@2026-10-02T11:25:17Z
show less
Port Scan
Hacking
๐ฉ๐ช
joharikop
2026-10-02 08:51:41
(2 days ago)
Nginx: WordPress/CMS probe (wp-admin, wp-login, xmlrpc). Automated ban via fail2ban nginx-cms-probes ...
show more
Nginx: WordPress/CMS probe (wp-admin, wp-login, xmlrpc). Automated ban via fail2ban nginx-cms-probes jail.
show less
Web App Attack
๐ฆ๐บ
aranguren.org
2026-08-02 18:57:54
(2 months ago)
45.89.242.101 - - [03/Aug/2026:04:57:52 +1000] "GET /dex.php HTTP/1.1" 404 16 "-" "Go-http-client/1. ...
show more
45.89.242.101 - - [03/Aug/2026:04:57:52 +1000] "GET /dex.php HTTP/1.1" 404 16 "-" "Go-http-client/1.1"
45.89.242.101 - - [03/Aug/2026:04:57:52 +1000] "GET /wp-admin/admin-ajax.php HTTP/1.1" 404 985 "-" "Go-http-client/1.1"
45.89.242.101 - - [03/Aug/2026:04:57:53 +1000] "GET //zwso.php HTTP/1.1" 404 16 "-" "Go-http-client/1.1"
45.89.242.101 - - [03/Aug/2026:04:57:53 +1000] "GET /wp-content/plugins/hellopress/wp_mna.php HTTP/1.1" 404 985 "-" "Go-http-client/1.1"
45.89.242.101 - - [03/Aug/2026:04:57:53 +1000] "GET /bolt.php HTTP/1.1" 404 16 "-" "Go-http-client/1.1"
45.89.242.101 - - [03/Aug/2026:04:57:53 +1000] "GET /cjfuns.php HTTP/1.1" 404 16 "-" "Go-http-client/1.1"
...
show less
Bad Web Bot
๐ช๐ธ
alferez
2026-08-02 03:37:28
(2 months ago)
Searching hacked php files
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 18:07:14
(2 months ago)
CrowdSec: crowdsecurity/http-probing | req: /ms-themes.php | 11 distinct paths | UA: Go-http-client/ ...
show more
CrowdSec: crowdsecurity/http-probing | req: /ms-themes.php | 11 distinct paths | UA: Go-http-client/2.0
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 13:44:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.89.242.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.89.242.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 09:44:05.712535 2026] [security2:error] [pid 3129:tid 3129] [client 45.89.242.101:55859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neh-media.com"] [uri "/.env"] [unique_id "akZrJc0upXIHzRaGqaIo_wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 06:42:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.89.242.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.89.242.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 02:41:58.843657 2026] [security2:error] [pid 6633:tid 6654] [client 45.89.242.101:43971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accreditedprojectmanager.com"] [uri "/.env"] [unique_id "akS2ttNoatLEj2ruHEPIEgAAAdM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-18 01:11:33
(3 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-06-17 18:36:00
(3 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
directorioeducativo.com
2026-06-17 16:43:03
(3 months ago)
GET URL: "/wp-includes/woocommerce-call.php"Agent: "Go-http-client/2.0"
Web App Attack
Anonymous
2026-04-08 11:39:42
(5 months ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-04-05 16:13:59
(5 months ago)
2026-04-05 18:13:58 ERROR util.AccessViolations - 45.89.242.101 report to fail2ban - action: block
. ...
show more
2026-04-05 18:13:58 ERROR util.AccessViolations - 45.89.242.101 report to fail2ban - action: block
...
show less
Hacking
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-16 21:15:24
(6 months ago)
(mod_security) mod_security (id:240000) triggered by 45.89.242.101 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.89.242.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 17:15:16.978372 2026] [security2:error] [pid 2471:tid 2471] [client 45.89.242.101:45541] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "87"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||paulaperez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "paulaperez.com"] [uri "/images/stories/themes.php"] [unique_id "abhy5LDXJ5h8Ih0xL259lAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-03-15 23:33:48
(6 months ago)
Aggressive web search of vulnerable pages: /routes/ /uploads/ /templates/beez3/ /wp-content/themes/d ...
show more
Aggressive web search of vulnerable pages: /routes/ /uploads/ /templates/beez3/ /wp-content/themes/digital-download/ /wp-content/plugins/wp-the ...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-02-28 17:31:51
(7 months ago)
5.649 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot