🇿🇦
vanderhost
2026-09-20 19:32:33
(15 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /wp-admin/css via rule: ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /wp-admin/css via rule: /wp-admin
show less
Web App Attack
Bad Web Bot
🇬🇷
setupgr
2026-09-20 15:52:09
(18 hours ago)
(mod_security) mod_security (id:11000011) triggered by 5.189.145.112 (FR/France/Bas-Rhin/Lauterbourg ...
show more
(mod_security) mod_security (id:11000011) triggered by 5.189.145.112 (FR/France/Bas-Rhin/Lauterbourg/-/[AS51167 Contabo GmbH]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:52:08.274964 2026] [security2:error] [pid 1025362:tid 1025464] [client 5.189.145.112:61364] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "contaboserver.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: vmi3577886.contaboserver.net"] [severity "CRITICAL"] [hostname "setworldup.com"] [uri "/wp-admin/css/"] [unique_id "arABKKYAA2s3JKp_0F2pvAAAApg"], referer: binance.com
show less
Port Scan
🇩🇪
nyt
2026-09-20 13:19:30
(21 hours ago)
Bad Web Bot, Web App Attack, ai-sus: Referrer indicates potential automated scanning activity
Bad Web Bot
Web App Attack
🇬🇷
setupgr
2026-09-20 12:14:30
(22 hours ago)
(mod_security) mod_security (id:11000011) triggered by 5.189.145.112 (FR/France/Bas-Rhin/Lauterbourg ...
show more
(mod_security) mod_security (id:11000011) triggered by 5.189.145.112 (FR/France/Bas-Rhin/Lauterbourg/-/[AS51167 Contabo GmbH]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:14:25.859286 2026] [security2:error] [pid 1025625:tid 1025734] [client 5.189.145.112:63169] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "contaboserver.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: vmi3577886.contaboserver.net"] [severity "CRITICAL"] [hostname "cpanagiotou.gr"] [uri "/wp-admin/css/"] [unique_id "aq_OIdOHfR6d3QshG8c_FQAAAUg"], referer: binance.com
show less
Port Scan
🇲🇾
Rizzy
2026-09-20 11:17:41
(23 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-20 08:09:20
(1 day ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_server_contact
Hacking
🇩🇪
nyt
2026-09-20 06:17:52
(1 day ago)
Bad Web Bot, Web App Attack, ai-sus: Referrer suggests potential automated scanning activity
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-20 05:30:10
(1 day ago)
[Sun Sep 20 15:30:09.621903 2026] [security2:error] [pid 880024] [client 5.189.145.112:58589] [clien ...
show more
[Sun Sep 20 15:30:09.621903 2026] [security2:error] [pid 880024] [client 5.189.145.112:58589] [client 5.189.145.112] ModSecurity: Access denied with code 403 (phase 4). Operator GE matched 4 at TX:outbound_anomaly_score. [file "/etc/modsecurity/crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf"] [line "77"] [id "959100"] [msg "Outbound Anomaly Score Exceeded (Total Score: 4)"] [ver "OWASP_CRS/3.3.4"] [tag "anomaly-evaluation"] [hostname "stkildashule.org.au"] [uri "/wp-content/uploads/2026/09/"] [unique_id "aq9vYYM4oTgQjjFKBbTgxwAAAA0"], referer: binance.com
...
show less
Web App Attack
🇲🇾
Rizzy
2026-09-19 08:58:53
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇬🇷
setupgr
2026-09-19 08:55:27
(2 days ago)
(mod_security) mod_security (id:11000011) triggered by 5.189.145.112 (FR/France/Bas-Rhin/Lauterbourg ...
show more
(mod_security) mod_security (id:11000011) triggered by 5.189.145.112 (FR/France/Bas-Rhin/Lauterbourg/-/[AS51167 Contabo GmbH]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Sep 19 11:55:22.709529 2026] [security2:error] [pid 473642:tid 473779] [client 5.189.145.112:58838] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "contaboserver.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: vmi3577886.contaboserver.net"] [severity "CRITICAL"] [hostname "ftiaxtomonosou.gr"] [uri "/wp-admin/css/"] [unique_id "aq5N-k7wYV1K07AfCkHWbQAAAxI"], referer: binance.com
show less
Port Scan
🇨🇭
backslash
2026-09-19 06:33:00
(2 days ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇫🇷
Baking333
2026-09-19 00:03:24
(2 days ago)
[redacted] 5.189.145.112 - - [19/Sep/2026:01:03:15 +0100] "GET /wp-admin/css/ HTTP/1.1" 301 5842 0/3 ...
show more
[redacted] 5.189.145.112 - - [19/Sep/2026:01:03:15 +0100] "GET /wp-admin/css/ HTTP/1.1" 301 5842 0/306 "[redacted]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 443 [redacted] 5.189.145.112 - - [19/Sep/2026:01:03:22 +0100] "GET /wp-admin/css HTTP/1.1" 302 6778 0/84194 "[redacted]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-18 22:23:07
(2 days ago)
Brute-Force
Web App Attack
🇪🇸
Gem
2026-09-18 22:11:56
(2 days ago)
Unauthorized web scan.
Web App Attack
🇪🇸
netfactotum
2026-09-18 22:04:11
(2 days ago)
Hacking
Web App Attack