๐ฌ๐ท
setupgr
2026-09-20 12:47:01
(2 days ago)
(mod_security) mod_security (id:11000011) triggered by 89.222.112.18 (NL/The Netherlands/North Holla ...
show more
(mod_security) mod_security (id:11000011) triggered by 89.222.112.18 (NL/The Netherlands/North Holland/Amsterdam/-/[AS212238 Datacamp Limited]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:46:58.138742 2026] [security2:error] [pid 1025368:tid 1025482] [client 89.222.112.18:61414] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "datapacket.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: unn-89-222-112-18.datapacket.com"] [severity "CRITICAL"] [hostname "asteriassantorini.com"] [uri "/wp-json/batch/v1"] [unique_id "aq_Vwj7CIh8S4jwxl9dlaQAAAk0"]
show less
Port Scan
๐ฉ๐ช
yvoictra
2026-09-20 12:44:14
(2 days ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-cve-probing
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-20 12:32:58
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-probing
Web App Attack
Hacking
๐ฉ๐ช
yitzhaq
2026-09-20 12:24:31
(2 days ago)
89.222.112.18 - - [20/Sep/2026:14:24:28 +0200] "POST /wp-json/batch/v1 HTTP/1.1" 403 4460 "-" "Mozil ...
show more
89.222.112.18 - - [20/Sep/2026:14:24:28 +0200] "POST /wp-json/batch/v1 HTTP/1.1" 403 4460 "-" "Mozilla/5.0 (compatible)"
89.222.112.18 - - [20/Sep/2026:14:24:28 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 4460 "-" "Mozilla/5.0 (compatible)"
show less
Web App Attack
Hacking
๐ฆ๐บ
A.i.D.A.N.N
2026-09-20 11:52:28
(2 days ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐บ๐ธ
factor1
2026-09-20 09:18:58
(2 days ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-20 07:45:01
(2 days ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-20 07:09:37
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ฌ๐ท
setupgr
2026-09-20 06:57:52
(2 days ago)
(mod_security) mod_security (id:11000011) triggered by 89.222.112.18 (NL/The Netherlands/North Holla ...
show more
(mod_security) mod_security (id:11000011) triggered by 89.222.112.18 (NL/The Netherlands/North Holland/Amsterdam/-/[AS212238 Datacamp Limited]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:57:51.306076 2026] [security2:error] [pid 1025362:tid 1025451] [client 89.222.112.18:49656] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "datapacket.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: unn-89-222-112-18.datapacket.com"] [severity "CRITICAL"] [hostname "cpanagiotou.gr"] [uri "/wp-json/batch/v1"] [unique_id "aq-D76YAA2s3JKp_0F2jVwAAApQ"]
show less
Port Scan
๐บ๐ธ
factor1
2026-09-11 08:56:10
(1 week ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐ฌ๐ท
setupgr
2026-09-11 08:49:10
(1 week ago)
(mod_security) mod_security (id:11000011) triggered by 89.222.112.18 (NL/The Netherlands/North Holla ...
show more
(mod_security) mod_security (id:11000011) triggered by 89.222.112.18 (NL/The Netherlands/North Holland/Amsterdam/-/[AS212238 Datacamp Limited]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:49:09.100571 2026] [security2:error] [pid 78625:tid 78805] [client 89.222.112.18:61705] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "datapacket.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: unn-89-222-112-18.datapacket.com"] [severity "CRITICAL"] [hostname "asteriassantorini.com"] [uri "/wp-json/batch/v1"] [unique_id "aqPAhfuqreqSm6QjW5QzagAAAtc"]
show less
Port Scan
๐ฆ๐บ
2000cn.com.au
2026-09-11 08:43:15
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-probing
Web App Attack
Hacking
๐ฌ๐ท
setupgr
2026-09-11 06:19:54
(1 week ago)
(mod_security) mod_security (id:11000011) triggered by 89.222.112.18 (NL/The Netherlands/North Holla ...
show more
(mod_security) mod_security (id:11000011) triggered by 89.222.112.18 (NL/The Netherlands/North Holland/Amsterdam/-/[AS212238 Datacamp Limited]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:19:51.117306 2026] [security2:error] [pid 28868:tid 29009] [client 89.222.112.18:54360] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "datapacket.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: unn-89-222-112-18.datapacket.com"] [severity "CRITICAL"] [hostname "cpanagiotou.gr"] [uri "/wp-json/batch/v1"] [unique_id "aqOdh2N7ngWM_dCK6WGetgAAAcg"]
show less
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-09-11 05:29:12
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฎ๐น
Progetto1
2026-09-11 04:55:03
(1 week ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack