π©πͺ
F242
2026-07-07 20:24:41
(1 month ago)
Wordpress soft lock
Web App Attack
π·πΊ
sms.ru
2026-06-08 23:21:34
(2 months ago)
/wp-admin/css/wp-login.php
Web App Attack
π«π·
Octopuce
2026-06-06 03:40:37
(3 months ago)
Aggressive web search of vulnerable pages: /themes/zMousse/otuz1.php /wp-content/edit-wolf.php /wp-c ...
show more
Aggressive web search of vulnerable pages: /themes/zMousse/otuz1.php /wp-content/edit-wolf.php /wp-content/plugins/ubh/up.php /wp-admin/images/ ...
show less
Web App Attack
πͺπΈ
pipeline.es
2026-06-06 03:23:27
(3 months ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
πͺπΈ
pipeline.es
2026-06-06 03:07:23
(3 months ago)
Web scanning / probing for vulnerable paths | URL: /wp-json/wp/v2/ | Evidence: www.viajesazahar.com ...
show more
Web scanning / probing for vulnerable paths | URL: /wp-json/wp/v2/ | Evidence: www.viajesazahar.com 45.95.243.119 - - [06/Jun/2026:05:06:58 +0200] \"GET /wp-json/wp/v2/ HTTP/1.1\" 404 212 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36\" GEOIP_COUNTRY_CODE=AT | ASN: Datacamp Limited | Country: AT
show less
Port Scan
Web App Attack
πΊπ¦
URAN Publishing Service
2026-06-06 02:01:40
(3 months ago)
45.95.243.119 - - [06/Jun/2026:05:01:40 +0300] "GET /wp-admin/css/ HTTP/1.1" 404 478 "-" "Mozilla/5. ...
show more
45.95.243.119 - - [06/Jun/2026:05:01:40 +0300] "GET /wp-admin/css/ HTTP/1.1" 404 478 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
45.95.243.119 - - [06/Jun/2026:05:01:40 +0300] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 404 478 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
π¬π§
consul.to
2026-06-05 21:00:26
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
π¬π§
consul.to
2026-06-04 12:34:50
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
dbmwebdesign
2026-05-27 09:55:03
(3 months ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
π―π΅
demonsword
2026-05-13 22:24:44
(3 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: ipleak.net:443
show less
Open Proxy
Port Scan
πΊπΈ
TPI-Abuse
2026-03-13 05:26:32
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.95.243.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.95.243.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 01:26:26.464973 2026] [security2:error] [pid 19044:tid 19044] [client 45.95.243.119:53061] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brazilianbikinis.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brazilianbikinis.com"] [uri "/backup/sql.sql"] [unique_id "abOgArENd-GXgRysUHN9TgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-04 11:41:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.95.243.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.95.243.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 06:41:35.860742 2026] [security2:error] [pid 30873:tid 30873] [client 45.95.243.119:35337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wendeenicole.com"] [uri "/old/sftp-config.json"] [unique_id "aagab3VcPknnXHfNFaZl3QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-03-03 05:03:07
(6 months ago)
trying wp-login.php/xmlrpc.php 76 times in 1 minutes
Brute-Force
Web App Attack
πΊπΈ
Penny Packer
2026-02-23 22:11:43
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-16 13:28:05
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.95.243.119 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.95.243.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 08:28:01.787825 2026] [security2:error] [pid 8127:tid 8127] [client 45.95.243.119:38837] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcointradingsquare.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcointradingsquare.com"] [uri "/backups/www.sql"] [unique_id "aZMbYfr5-fvvHnlsfCyOoAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack