๐ฎ๐ฉ
bps-statistics
2026-06-20 10:37:17
(1 month ago)
Remote Shell Reconnaisance: "2026-06-20T17:37:17.095+07:00" "/ALFA_DATA/alfacgiapi/perl.alfa" "64.89 ...
show more
Remote Shell Reconnaisance: "2026-06-20T17:37:17.095+07:00" "/ALFA_DATA/alfacgiapi/perl.alfa" "64.89.162.167" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
show less
Web App Attack
Brute-Force
๐ฉ๐ช
LRob
2026-06-20 01:15:12
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฆ๐บ
paulshipley.com.au
2026-06-19 20:24:23
(1 month ago)
[Sat Jun 20 06:24:21.822736 2026] [security2:error] [pid 707663] [client 64.89.162.167:60101] [clien ...
show more
[Sat Jun 20 06:24:21.822736 2026] [security2:error] [pid 707663] [client 64.89.162.167:60101] [client 64.89.162.167] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/wp-plain.php"] [unique_id "ajWldanQm2M3mlRgB6fn5QAAABs"], referer: www.google.com
...
show less
Web App Attack
Anonymous
2026-06-19 20:15:44
(1 month ago)
[19/Jun/2026:23:15:44 +0300] 178190014478.349192 64.89.162.167 64086 148.251.76.218 80
[19/Jun/2026: ...
show more
[19/Jun/2026:23:15:44 +0300] 178190014478.349192 64.89.162.167 64086 148.251.76.218 80
[19/Jun/2026:23:15:44 +0300] 178190014418.105333 64.89.162.167 64122 148.251.76.218 80
show less
Web App Attack
๐ฉ๐ช
Viveronese
2026-06-19 08:21:57
(1 month ago)
HTTP vulnerability scanning
Web App Attack
๐ฌ๐ท
setupgr
2026-06-19 08:10:00
(1 month ago)
(mod_security) mod_security (id:1000001) triggered by 64.89.162.167 (NL/The Netherlands/Limburg/Eyge ...
show more
(mod_security) mod_security (id:1000001) triggered by 64.89.162.167 (NL/The Netherlands/Limburg/Eygelshoven/-/[AS198584 PIO-HOSTING]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Fri Jun 19 11:09:58.483103 2026] [security2:error] [pid 202885:tid 211519] [remote 64.89.162.167:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "93"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/seotheme/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "santoriniicon.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ajT5Vkrlp52aw72Tw8e68wABFx4"], referer: www.google.com
show less
Port Scan
๐ซ๐ท
SpaceHost-Server
2026-06-18 22:33:41
(1 month ago)
Brute-Force
Web App Attack
๐ฉ๐ช
roxyapi
2026-06-18 20:28:04
(1 month ago)
Honeypot: automated vulnerability scan / web app attack. Last probe: GET /wp-content/plugins/fix/up. ...
show more
Honeypot: automated vulnerability scan / web app attack. Last probe: GET /wp-content/plugins/fix/up.php
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
agenciahypelab.com.br
2026-06-18 19:45:18
(1 month ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ซ๐ท
dynamix
2026-06-18 17:18:21
(1 month ago)
Multiple WAF Violations
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-18 14:27:25
(1 month ago)
64.89.162.167 - - [18/Jun/2026:17:27:24 +0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 4 ...
show more
64.89.162.167 - - [18/Jun/2026:17:27:24 +0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 763 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
64.89.162.167 - - [18/Jun/2026:17:27:24 +0300] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 707 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
maxpower
2026-06-18 14:16:06
(1 month ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 64.89.162.167 (US/United States/-): 2 in the last 3 ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 64.89.162.167 (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 64.89.162.167 - - [18/Jun/2026:16:16:02 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 404 5378 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "64.89.162.167" host=www.marialauracaselli.com
64.89.162.167 - - [18/Jun/2026:16:16:03 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 404 5378 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "64.89.162.167" host=www.marialauracaselli.com
show less
Port Scan
๐ณ๐ฑ
Site.eu
2026-06-18 14:03:20
(1 month ago)
Excessive multi-domain requests
Brute-Force
๐ฒ๐พ
Rizzy
2026-06-18 12:37:34
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
paissangroup
2026-06-18 11:46:25
(1 month ago)
Multiple WAF Violations
Web App Attack