Anonymous
2026-06-01 14:28:13
(5 days ago)
ALFA.TEaM.Web.Shell
Web App Attack
๐บ๐ธ
gu-alvareza
2026-05-23 07:05:13
(2 weeks ago)
ALFA.TEaM.Web.Shell
Hacking
๐ฆ๐บ
paulshipley.com.au
2026-05-23 03:13:44
(2 weeks ago)
[Sat May 23 13:13:43.628310 2026] [security2:error] [pid 822706] [client 45.94.31.221:60667] [client ...
show more
[Sat May 23 13:13:43.628310 2026] [security2:error] [pid 822706] [client 45.94.31.221:60667] [client 45.94.31.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "talentaymerch.com.au"] [uri "/wp-plain.php"] [unique_id "ahEbZ5J2udyhivfFo-N61gAAAAM"], referer: www.google.com
...
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-05-23 02:58:39
(2 weeks ago)
[Sat May 23 12:58:38.370044 2026] [security2:error] [pid 811193] [client 45.94.31.221:58063] [client ...
show more
[Sat May 23 12:58:38.370044 2026] [security2:error] [pid 811193] [client 45.94.31.221:58063] [client 45.94.31.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "rjryanpartners.com.au"] [uri "/wp-plain.php"] [unique_id "ahEX3reMSMDDB5h5YJ1aVwAAAAY"], referer: www.google.com
...
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-05-23 02:16:20
(2 weeks ago)
[Sat May 23 12:16:20.068556 2026] [security2:error] [pid 807067] [client 45.94.31.221:57788] [client ...
show more
[Sat May 23 12:16:20.068556 2026] [security2:error] [pid 807067] [client 45.94.31.221:57788] [client 45.94.31.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dlcarterauthor.com"] [uri "/wp-plain.php"] [unique_id "ahEN9FGC2YIGE8X-t0Oh8gAAAAo"], referer: www.google.com
...
show less
Web App Attack
๐ฌ๐ง
Greg Poulson
2026-05-23 01:28:25
(2 weeks ago)
Our website was hit by this DDOS at a rate of 8 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐ฌ๐ง
andypiper
2026-05-23 01:01:20
(2 weeks ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-05-23 00:45:03
(2 weeks ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
kosada.com
2026-05-23 00:13:00
(2 weeks ago)
Web vulnerability probing: /plugins/content/apismtp/apismtp.php
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-05-22 22:24:26
(2 weeks ago)
vulnerability scan
Web App Attack
๐ฆ๐บ
clapper
2026-05-22 20:08:29
(2 weeks ago)
(mod_security) mod_security (id:980001) triggered by 45.94.31.221 (45.94.31.221.powered.by.rdp.sh): ...
show more
(mod_security) mod_security (id:980001) triggered by 45.94.31.221 (45.94.31.221.powered.by.rdp.sh): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
itsolon
2026-05-22 19:20:26
(2 weeks ago)
[22/May/2026:21:20:25 +0200] 177947762593.713603 45.94.31.221 56569 217.154.7.177 443
[22/May/2026:2 ...
show more
[22/May/2026:21:20:25 +0200] 177947762593.713603 45.94.31.221 56569 217.154.7.177 443
[22/May/2026:21:20:25 +0200] 177947762564.465511 45.94.31.221 54588 217.154.7.177 443
[22/May/2026:21:20:25 +0200] 177947762554.440955 45.94.31.221 54609 217.154.7.177 443
[22/May/2026:21:20:25 +0200] 177947762589.697329 45.94.31.221 54601 217.154.7.177 443
[22/May/2026:21:20:25 +0200] 177947762535.693745 45.94.31.221 54608 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐จ๐ฆ
SoteriaCovenant
2026-05-22 19:15:01
(2 weeks ago)
Automated probe: /wp-content/plugins/fix/up.php on Soteria Global infrastructure. No vulnerable soft ...
show more
Automated probe: /wp-content/plugins/fix/up.php on Soteria Global infrastructure. No vulnerable software present.
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-22 18:28:30
(2 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.94.31.221 (45.94.31.221.powered. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.94.31.221 (45.94.31.221.powered.by.rdp.sh): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-05-22 18:28:26
(2 weeks ago)
45.94.31.221 - - [23/May/2026:02:28:21 +0800] "POST /wp-plain.php HTTP/1.1" 404 360 "www.google.com" ...
show more
45.94.31.221 - - [23/May/2026:02:28:21 +0800] "POST /wp-plain.php HTTP/1.1" 404 360 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
45.94.31.221 - - [23/May/2026:02:28:21 +0800] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 61399 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
45.94.31.221 - - [23/May/2026:02:28:21 +0800] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 60968 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
45.94.31.221 - - [23/May/2026:02:28:21 +0800] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 404 61399 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/
...
show less
Bad Web Bot
Web App Attack