๐ฆ๐บ
paulshipley.com.au
2026-07-31 18:23:11
(3 hours ago)
[Sat Aug 01 04:23:10.671762 2026] [security2:error] [pid 682444] [client 91.124.88.68:35029] [client ...
show more
[Sat Aug 01 04:23:10.671762 2026] [security2:error] [pid 682444] [client 91.124.88.68:35029] [client 91.124.88.68] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/"] [unique_id "amzoDvYRze7TKDe63cLYugAAAAc"]
...
show less
Web App Attack
๐น๐ท
neron
2026-07-31 11:06:18
(10 hours ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-30 00:48:37
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐น๐ท
neron
2026-07-29 00:19:38
(2 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-27 02:20:24
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-07-27 02:15:00
(4 days ago)
91.124.88.68 - - [27/Jul/2026:04:14:52 +0200] "GET /wp-admin/css/colors/blue/pass.php HTTP/1.1" 301 ...
show more
91.124.88.68 - - [27/Jul/2026:04:14:52 +0200] "GET /wp-admin/css/colors/blue/pass.php HTTP/1.1" 301 575 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
91.124.88.68 - - [27/Jul/2026:04:14:53 +0200] "GET /wp-includes/l10n/class-wp-translations-interface.php HTTP/1.1" 301 613 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"
91.124.88.68 - - [27/Jul/2026:04:14:53 +0200] "GET /wp-includes/assets/about5.php HTTP/1.1" 301 567 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
91.124.88.68 - - [27/Jul/2026:04:14:53 +0200] "GET /wp-admin/maint/lint-branch.php HTTP/1.1" 301 569 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"
91.124.88.68 - - [27/Jul/2026:04:14:54 +0200] "GET /wp-content/cong.php HTTP/1.1" 301 547 "-" "Mozi
show less
Web App Attack
Brute-Force
๐ซ๐ท
Octopuce
2026-07-23 19:42:39
(1 week ago)
Aggressive web search of vulnerable pages: /autoload_classmap/function.php /wp-includes/item.php /as ...
show more
Aggressive web search of vulnerable pages: /autoload_classmap/function.php /wp-includes/item.php /assets/index.php /.well-known/pki-validation/ ...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-07-20 08:03:18
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 04:28:12
(1 week ago)
(mod_security) mod_security (id:240000) triggered by 91.124.88.68 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 91.124.88.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 00:28:06.824464 2026] [security2:error] [pid 23660:tid 23660] [client 91.124.88.68:31969] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||thermalsoftware.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "thermalsoftware.com"] [uri "/images/stories/themes.php"] [unique_id "alsA1rC4cjxc0fEPhYE4XwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-18 04:18:35
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-07-17 21:43:03
(2 weeks ago)
91.124.88.68 - - [17/Jul/2026:22:42:46 +0100] "GET /.trash7206/index.php HTTP/1.1" 301 162 "-" "Mozi ...
show more
91.124.88.68 - - [17/Jul/2026:22:42:46 +0100] "GET /.trash7206/index.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36"
91.124.88.68 - - [17/Jul/2026:22:42:46 +0100] "GET /storage/framework/views/core.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
91.124.88.68 - - [17/Jul/2026:22:42:47 +0100] "GET /wp-content/plugins/filester/assets/css/404.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
...
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-07-17 19:00:51
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-07-17 14:51:45
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-07 14:44:39
(3 weeks ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
Octopuce
2026-06-29 20:49:35
(1 month ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/aatdgetgdg/main.php /license.php /sty ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/aatdgetgdg/main.php /license.php /style2.php /functions.php /wp-includes/SimpleP ...
show less
Web App Attack