๐จ๐ฟ
huginet
2026-06-20 19:47:19
(1 month ago)
64.89.162.167 - - [20/Jun/2026:21:47:18 +0200] "GET / HTTP/1.1" 403 17542 "-" "Mozlila/5.0 (Linux; A ...
show more
64.89.162.167 - - [20/Jun/2026:21:47:18 +0200] "GET / HTTP/1.1" 403 17542 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
64.89.162.167 - - [20/Jun/2026:21:47:18 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17542 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web Spam
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-20 19:45:12
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐ฉ๐ช
ut-addicted.com
2026-06-20 18:37:32
(1 month ago)
\[Sat Jun 20 20:37:29.755896 2026\] \[:error\] \[pid 32433:tid 139785800742656\] \[client 64.89.162. ...
show more
\[Sat Jun 20 20:37:29.755896 2026\] \[:error\] \[pid 32433:tid 139785800742656\] \[client 64.89.162.167:59094\] \[client 64.89.162.167\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "www.ut-addicted.com"\] \[uri "/wp-plain.php"\] \[unique_id "ajbd6coOWQmbJdHP20MaWwAAAIo"\], referer: www.google.com
show less
Brute-Force
Web App Attack
Anonymous
2026-06-20 17:36:56
(1 month ago)
64.89.162.167 - - [20/Jun/2026:19:36:55 +0200] "GET /wp-content/plugins/fix/ HTTP/1.1" 301 169 "-" " ...
show more
64.89.162.167 - - [20/Jun/2026:19:36:55 +0200] "GET /wp-content/plugins/fix/ HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
show less
Web App Attack
๐ง๐ช
madeit
2026-06-20 17:24:38
(1 month ago)
Web App Attack
๐ฉ๐ช
LRob
2026-06-20 16:30:13
(1 month ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ฉ๐ช
maxpower
2026-06-20 14:42:51
(1 month ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 64.89.162.167 (US/United States/-): 2 in the last 3 ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 64.89.162.167 (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 64.89.162.167 - - [20/Jun/2026:16:42:48 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 404 6604 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "64.89.162.167" host=ilfaro.focusabruzzo.eu
64.89.162.167 - - [20/Jun/2026:16:42:48 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 404 6604 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "64.89.162.167" host=ilfaro.focusabruzzo.eu
show less
Port Scan
๐ซ๐ท
dynamix
2026-06-20 13:45:08
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-06-20 12:50:04
(1 month ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-06-20 11:44:35
(1 month ago)
2026/06/20 14:44:34 [error] 3781430#3781430: *29228 FastCGI sent in stderr: "Primary script unknown" ...
show more
2026/06/20 14:44:34 [error] 3781430#3781430: *29228 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 64.89.162.167, server: oh6ah.fi, request: "GET /wp-content/plugins/fix/up.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/oh6ah.fi.sock:", host: "oh6ah.fi"
2026/06/20 14:44:34 [error] 3781430#3781430: *29234 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 64.89.162.167, server: oh6ah.fi, request: "POST /wp-plain.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/oh6ah.fi.sock:", host: "oh6ah.fi", referrer: "www.google.com"
...
show less
Web App Attack
๐ฉ๐ช
raph
2026-06-20 10:59:12
(1 month ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-06-20 10:47:38
(1 month ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 64.89.162.167 (US/United States/-): 2 in the last 3 ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 64.89.162.167 (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 64.89.162.167 - - [20/Jun/2026:12:47:29 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 404 8482 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "64.89.162.167" host=ctpescara.it
64.89.162.167 - - [20/Jun/2026:12:47:33 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 404 8482 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "64.89.162.167" host=ctpescara.it
show less
Port Scan
๐ฎ๐ฉ
bps-statistics
2026-06-20 10:37:17
(1 month ago)
Remote Shell Reconnaisance: "2026-06-20T17:37:17.095+07:00" "/ALFA_DATA/alfacgiapi/perl.alfa" "64.89 ...
show more
Remote Shell Reconnaisance: "2026-06-20T17:37:17.095+07:00" "/ALFA_DATA/alfacgiapi/perl.alfa" "64.89.162.167" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
show less
Web App Attack
Brute-Force
๐ฉ๐ช
LRob
2026-06-20 01:15:12
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฆ๐บ
paulshipley.com.au
2026-06-19 20:24:23
(1 month ago)
[Sat Jun 20 06:24:21.822736 2026] [security2:error] [pid 707663] [client 64.89.162.167:60101] [clien ...
show more
[Sat Jun 20 06:24:21.822736 2026] [security2:error] [pid 707663] [client 64.89.162.167:60101] [client 64.89.162.167] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/wp-plain.php"] [unique_id "ajWldanQm2M3mlRgB6fn5QAAABs"], referer: www.google.com
...
show less
Web App Attack