๐ญ๐บ
miszterx.hu
2026-09-16 08:47:12
(20 hours ago)
XORP (haproxy): 8x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 8x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ง๐ช
taivas.nl
2026-09-16 04:34:32
(1 day ago)
Many_bad_calls
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-15 20:49:01
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-09-15 20:48:46
(1 day ago)
65.21.77.47 - - [16/Sep/2026:04:48:34 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 46451 "-" "Mozill ...
show more
65.21.77.47 - - [16/Sep/2026:04:48:34 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 46451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - [16/Sep/2026:04:48:41 +0800] "GET /wp-config.php~ HTTP/1.1" 404 46451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - [16/Sep/2026:04:48:42 +0800] "GET /wp-config.php.save HTTP/1.1" 404 46451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - [16/Sep/2026:04:48:43 +0800] "GET /wp-config.php.old HTTP/1.1" 404 46523 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - [16/Sep/2026:04:48:44 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 46451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 20:38:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 65.21.77.47 (static.47.77.21.65.clients.your-se ...
show more
(mod_security) mod_security (id:210492) triggered by 65.21.77.47 (static.47.77.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:38:52.967127 2026] [security2:error] [pid 5829:tid 5829] [client 65.21.77.47:52778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehealthyplaceclayton.com"] [uri "/wp-config.php.bak"] [unique_id "aqms3EiAKAGP8bsqtmOvnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:15:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 65.21.77.47 (static.47.77.21.65.clients.your-se ...
show more
(mod_security) mod_security (id:210492) triggered by 65.21.77.47 (static.47.77.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:15:17.891919 2026] [security2:error] [pid 6934:tid 6959] [client 65.21.77.47:58714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reghay.com"] [uri "/wp-config.php.bak"] [unique_id "aql9JakqeDDCl2GMw67DCAAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 15:08:22
(1 day ago)
[ti-01ov] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 65. ...
show more
[ti-01ov] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 65.21.77.47 - - \[15/Sep/2026:11:02:04 +0200\] "GET /wp-config.php.save HTTP/1.1" 301 5721 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - \[15/Sep/2026:11:02:04 +0200\] "GET /wp-config.php.save HTTP/1.1" 404 88917 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
solution.it
2026-09-15 10:57:15
(1 day ago)
[Tue Sep 15 12:57:14.886521 2026] [php7:error] [pid 1722063:tid 1722063] [client 65.21.77.47:38178] ...
show more
[Tue Sep 15 12:57:14.886521 2026] [php7:error] [pid 1722063:tid 1722063] [client 65.21.77.47:38178] script '/var/www/html/www.craccaaltesoro.it/phpinfo.php' not found or unable to stat
show less
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-15 10:50:34
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TAY
2026-09-15 10:47:40
(1 day ago)
65.21.77.47 - - [15/Sep/2026:18:47:33 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 34906 "-" "Mozill ...
show more
65.21.77.47 - - [15/Sep/2026:18:47:33 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 34906 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - [15/Sep/2026:18:47:34 +0800] "GET /wp-config.php~ HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - [15/Sep/2026:18:47:35 +0800] "GET /wp-config.php.save HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - [15/Sep/2026:18:47:36 +0800] "GET /wp-config.php.old HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
65.21.77.47 - - [15/Sep/2026:18:47:39 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 34922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko
...
show less
Brute-Force
๐ซ๐ท
dynamix
2026-09-15 10:42:43
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 10:31:38
(1 day ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 65.21.77.47 - - [15/Sep/2026:12:25:08 +0200] "GET /wp-config.php.save HTTP/1.1" 301 6344 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-15 10:27:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 65.21.77.47 (FI/Finland/static.47.77.21.65.clie ...
show more
(mod_security) mod_security (id:210492) triggered by 65.21.77.47 (FI/Finland/static.47.77.21.65.clients.your-server.de): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:24:57
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 65.21.77.47 (static.47.77.21.65.clients.your-se ...
show more
(mod_security) mod_security (id:949110) triggered by 65.21.77.47 (static.47.77.21.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:24:49.342494 2026] [security2:error] [pid 7742:tid 7742] [client 65.21.77.47:59394] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "delcano.org"] [uri "/wp-config.php.bak"] [unique_id "aqkc8QbegHXsDqD7lX_c6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-15 09:32:17
(1 day ago)
Bad_requests
Bad Web Bot