π«π·
tilellit.pro
2026-06-27 09:37:21
(1 day ago)
Fail2Ban banned 65.111.20.203 for security violations in jail wp-armour. Log: 2026/06/27 09:37:21 [e ...
show more
Fail2Ban banned 65.111.20.203 for security violations in jail wp-armour. Log: 2026/06/27 09:37:21 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 65.111.20.203 | Target: wplogin" , client: 65.111.20.203, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
π¬π·
setupgr
2026-06-25 04:53:12
(3 days ago)
(mod_security) mod_security (id:900001) triggered by 65.111.20.203 (BR/Brazil/SΓΒ£o Paulo/SΓΒ£o Paulo/ ...
show more
(mod_security) mod_security (id:900001) triggered by 65.111.20.203 (BR/Brazil/SΓΒ£o Paulo/SΓΒ£o Paulo/-/[AS200373 DREI-K-TECH-GMBH]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Thu Jun 25 07:53:10.653813 2026] [security2:error] [pid 358184:tid 358217] [client 65.111.20.203:32039] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "75"] [id "900001"] [msg "Blocked WP Login attempt on domain: mail.babis.photo"] [severity "CRITICAL"] [tag "security"] [hostname "mail.babis.photo"] [uri "/wp-login.php"] [unique_id "ajy0NqO2mzdLeHxqn3riCwAAAUE"], referer: https://mail.babis.photo/wp-login.php
show less
Port Scan
π«π·
ELYAZ
2026-06-24 06:33:57
(4 days ago)
(y4) Failed scan -byebye- from 65.111.20.203 (BR/Brazil/-): (CF_ENABLE)
Hacking
π«π·
ELYAZ
2026-06-23 03:06:49
(5 days ago)
(y4) Failed scan -byebye- from 65.111.20.203 (BR/Brazil/-): (CF_ENABLE)
Hacking
π«π·
ELYAZ
2026-06-21 09:40:36
(1 week ago)
(y4) Failed scan -byebye- from 65.111.20.203 (BR/Brazil/-): (CF_ENABLE)
Hacking
π¬π·
setupgr
2026-06-19 00:01:44
(1 week ago)
(mod_security) mod_security (id:900001) triggered by 65.111.20.203 (BR/Brazil/SΓΒ£o Paulo/SΓΒ£o Paulo/ ...
show more
(mod_security) mod_security (id:900001) triggered by 65.111.20.203 (BR/Brazil/SΓΒ£o Paulo/SΓΒ£o Paulo/-/[AS200373 DREI-K-TECH-GMBH]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Fri Jun 19 03:01:40.348614 2026] [security2:error] [pid 2277:tid 2447] [client 65.111.20.203:50815] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "75"] [id "900001"] [msg "Blocked WP Login attempt on domain: babis.photo"] [severity "CRITICAL"] [tag "security"] [hostname "babis.photo"] [uri "/wp-login.php"] [unique_id "ajSG5FVjV5VR3hAZ4rmKVwAAAFU"], referer: https://babis.photo/wp-login.php
show less
Port Scan
π«π·
ELYAZ
2026-06-18 19:36:55
(1 week ago)
(y4) Failed scan -byebye- from 65.111.20.203 (BR/Brazil/-): (CF_ENABLE)
Hacking
Anonymous
2026-06-18 19:16:00
(1 week ago)
Web attack blocked by Wordfence on www.charlesquaedvlieg.nl (1 hit). Reported by CRMON.
Web App Attack
π¬π·
setupgr
2026-06-16 23:06:08
(1 week ago)
(mod_security) mod_security (id:900001) triggered by 65.111.20.203: 1 in the last 86400 secs; Ports: ...
show more
(mod_security) mod_security (id:900001) triggered by 65.111.20.203: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jun 17 02:06:08.314247 2026] [security2:error] [pid 2210175:tid 2210238] [client 65.111.20.203:39545] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "75"] [id "900001"] [msg "Blocked WP Login attempt on domain: asteriassantorini.com"] [severity "CRITICAL"] [tag "security"] [hostname "asteriassantorini.com"] [uri "/wp-login.php"] [unique_id "ajHW4H9oGssBgNwsPFslrgAAAEo"], referer: https://asteriassantorini.com/wp-login.php
show less
Port Scan
π¬π§
spamverify.com
2026-06-16 08:40:13
(1 week ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
π¬π·
setupgr
2026-06-15 22:00:28
(1 week ago)
(mod_security) mod_security (id:900001) triggered by 65.111.20.203: 1 in the last 86400 secs; Ports: ...
show more
(mod_security) mod_security (id:900001) triggered by 65.111.20.203: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Tue Jun 16 01:00:27.509783 2026] [security2:error] [pid 1917012:tid 1917154] [client 65.111.20.203:56757] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "74"] [id "900001"] [msg "Blocked WP Login attempt on domain: mail.ions.gr"] [severity "CRITICAL"] [tag "security"] [hostname "mail.ions.gr"] [uri "/wp-login.php"] [unique_id "ajB1-0CXHuxGK7C8F7o8GAAAAFI"], referer: https://mail.ions.gr/wp-login.php
show less
Port Scan
π³πΏ
billyborsht
2026-06-15 00:45:39
(1 week ago)
2026-06-15T12:45:39.118727+12:00 southern wordpress(temukarau.nz)[794267]: Authentication attempt fo ...
show more
2026-06-15T12:45:39.118727+12:00 southern wordpress(temukarau.nz)[794267]: Authentication attempt for unknown user admin from 65.111.20.203
...
show less
Hacking
Web App Attack
π«π·
ELYAZ
2026-06-11 13:41:42
(2 weeks ago)
(y4) Failed scan -byebye- from 65.111.20.203 (BR/Brazil/-): (CF_ENABLE)
Hacking
πΊπΈ
kosada.com
2026-06-09 19:46:30
(2 weeks ago)
Web password guessing
Brute-Force
πΊπΈ
TPI-Abuse
2026-02-09 18:47:35
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.20.203 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.20.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 13:47:27.117637 2026] [security2:error] [pid 903305:tid 903305] [client 65.111.20.203:25779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fxbgsanta.com"] [uri "/.env"] [unique_id "aYorv3y9zWIlpKtZJktZXQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack