π§π·
Peregrine
2026-06-15 03:14:22
(1 month ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 64.89.162.167 104.23.172.73 - - [13/Jun/2026:04:54: ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 64.89.162.167 104.23.172.73 - - [13/Jun/2026:04:54:40 -0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 18193
show less
Bad Web Bot
π¬π·
setupgr
2026-06-15 02:16:25
(1 month ago)
(mod_security) mod_security (id:1000001) triggered by 64.89.162.167: 1 in the last 86400 secs; Ports ...
show more
(mod_security) mod_security (id:1000001) triggered by 64.89.162.167: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Mon Jun 15 05:16:25.747792 2026] [security2:error] [pid 921870:tid 921994] [client 64.89.162.167:51809] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "92"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/seotheme/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "babis.photo"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ai9geSiyK_EXlfCi56eRNgAAAEs"], referer: www.google.com
show less
Port Scan
π²πΎ
Rizzy
2026-06-15 01:34:36
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π«π·
dynamix
2026-06-15 01:09:03
(1 month ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-06-14 22:55:17
(1 month ago)
Multiple, malicious web requests detected
Port Scan
Hacking
πΉπ
thaizone.com
2026-06-14 20:23:56
(1 month ago)
Brute Force Attack on a Web Resources #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
π¦πΊ
clapper
2026-06-14 19:57:40
(1 month ago)
(mod_security) mod_security (id:980001) triggered by 64.89.162.167 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:980001) triggered by 64.89.162.167 (US/United States/-): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
Anonymous
2026-06-14 19:48:20
(1 month ago)
$f2bV_matches
Brute-Force
π©πͺ
london2038.com
2026-06-14 15:23:33
(1 month ago)
Probing for exploits
64.89.162.167 - - [14/Jun/2026:17:23:29 +0200] "GET / HTTP/1.1" 204 0 "-" "Mozl ...
show more
Probing for exploits
64.89.162.167 - - [14/Jun/2026:17:23:29 +0200] "GET / HTTP/1.1" 204 0 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
64.89.162.167 - - [14/Jun/2026:17:23:29 +0200] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 422 0 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
show less
Hacking
Web App Attack
π©πͺ
psauxit
2026-06-14 15:13:02
(1 month ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking
πΊπΈ
Starburst SysOp Team
2026-06-14 12:38:37
(1 month ago)
Found User-Agent associated with security scanner. Matched phrase "Mozlila" at REQUEST_HEADERS:User- ...
show more
Found User-Agent associated with security scanner. Matched phrase "Mozlila" at REQUEST_HEADERS:User-Agent. (913100-mnz6-1)
show less
Hacking
Bad Web Bot
π¬π·
setupgr
2026-06-14 12:37:02
(1 month ago)
(mod_security) mod_security (id:1000001) triggered by 64.89.162.167: 1 in the last 86400 secs; Ports ...
show more
(mod_security) mod_security (id:1000001) triggered by 64.89.162.167: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Sun Jun 14 15:37:00.801975 2026] [security2:error] [pid 922089:tid 922137] [client 64.89.162.167:59806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "92"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/seotheme/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "asteriassantorini.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ai6gbI2186Wa_UvIHKio5AAAAZU"], referer: www.google.com
show less
Port Scan
πΊπΈ
agenciahypelab.com.br
2026-06-14 11:08:26
(1 month ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
π§π·
dominioz
2026-06-14 10:21:38
(1 month ago)
2026-06-14 10:21:21 POST /wp-plain.php - - 64.89.162.167 HTTP/1.1 Mozilla/5.0+(Linux;+Android+7.0;+S ...
show more
2026-06-14 10:21:21 POST /wp-plain.php - - 64.89.162.167 HTTP/1.1 Mozilla/5.0+(Linux;+Android+7.0;+SM-G892A+Bulid/NRD90M;+wv)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Version/4.0+Chrome/60.0.3112.107+Moblie+Safari/537.36 www.google.com 404 40868
2026-06-14 10:21:21 GET /wp-content/themes/seotheme/db.php u - 64.89.162.167 HTTP/1.1 Mozlila/5.0+(Linux;+Android+7.0;+SM-G892A+Bulid/NRD90M;+wv)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Version/4.0+Chrome/60.0.3112.107+Moblie+Safari/537.36 www.google.com 404 40868
2026-06-14 10:21:21 POST /ALFA_DATA/alfacgiapi/perl.alfa - - 64.89.162.167 HTTP/1.1 Mozlila/5.0+(Linux;+Android+7.0;+SM-G892A+Bulid/NRD90M;+wv)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Version/4.0+Chrome/60.0.3112.107+Moblie+Safari/537.36 www.google.com 404 40868
2026-06-14 10:21:24 GET /wp-content/plugins/fix/up.php - - 64.89.162.167 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/85.0.4183.102+Safari/537.36 - 404 40868
...
show less
Web App Attack
πΊπΈ
nationaleventpros.com
2026-06-14 08:00:54
(1 month ago)
vulnerability scan
Web App Attack