๐ฉ๐ช
4server
2026-07-27 20:55:56
(3 hours ago)
[MonJul2722:55:53.6021452026][security2:error][pid3427189:tid3427302][client91.219.237.39:0]ModSecur ...
show more
[MonJul2722:55:53.6021452026][security2:error][pid3427189:tid3427302][client91.219.237.39:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"sanierung-pilzen-schimmel.ch\"][uri\"/index.php\"][unique_id\"amfF2TtZBdwU5zzcoDzr6QAAAQI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐น๐ท
neron
2026-07-27 20:19:38
(4 hours ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-27 14:27:35
(10 hours ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
๐ซ๐ท
DUBREUIL
2026-07-27 11:35:00
(13 hours ago)
As always with Hungary tor exit node
DDoS Attack
Open Proxy
Port Scan
Brute-Force
Web App Attack
SSH
Hacking
SQL Injection
๐ช๐ธ
librebit
2026-07-27 11:11:36
(13 hours ago)
Brute force
Brute-Force
๐ฆ๐น
nomzamo
2026-07-27 09:31:39
(15 hours ago)
Fail2Ban reported: nginx-noscript
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 02:43:22
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 91.219.237.39 (hungary.exit.maxzrbn.it): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 91.219.237.39 (hungary.exit.maxzrbn.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 22:43:16.920973 2026] [security2:error] [pid 3914838:tid 3914838] [client 91.219.237.39:43545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allfloridamedia.com"] [uri "/wp-content/plugins/recent-backups/download-file.php"] [unique_id "ambFxPjGTxX87wz7W_V_ZAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-07-26 17:50:51
(1 day ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
jakob
2026-07-24 15:59:23
(3 days ago)
modsecurity Alert: Restricted File Access Attempt
Hacking
๐น๐ท
neron
2026-07-24 15:30:03
(3 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
Anonymous
2026-07-16 13:01:00
(1 week ago)
2026-07-16 05:01:16,609 fail2ban.actions [3625835]: NOTICE [tor] Ban 91.219.237.39
2026-07-1 ...
show more
2026-07-16 05:01:16,609 fail2ban.actions [3625835]: NOTICE [tor] Ban 91.219.237.39
2026-07-16 08:00:35,973 fail2ban.actions [3625835]: NOTICE [tor] Ban 91.219.237.39
2026-07-16 11:00:24,615 fail2ban.actions [3625835]: NOTICE [tor] Ban 91.219.237.39
2026-07-16 13:01:48,284 fail2ban.actions [3625835]: NOTICE [tor] Ban 91.219.237.39
2026-07-16 16:00:59,851 fail2ban.actions [3625835]: NOTICE [tor] Ban 91.219.237.39
show less
Brute-Force
๐ง๐ท
ICS Labs
2026-07-06 13:13:22
(3 weeks ago)
ICS Labs identified 91.219.237.39 as a malicious indicator from threat intelligence.
DDoS Attack
Port Scan
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-27 16:05:32
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 91.219.237.39 (hungary.exit.maxzrbn.it): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 91.219.237.39 (hungary.exit.maxzrbn.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 12:05:25.496035 2026] [security2:error] [pid 26791:tid 26791] [client 91.219.237.39:51045] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pulleasy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pulleasy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aj_0xaRxdQw_spWSAnkXkAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-06-25 17:55:02
(1 month ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 03:14:05
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 91.219.237.39 (hungary.exit.maxzrbn.it): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 91.219.237.39 (hungary.exit.maxzrbn.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 23:13:57.202450 2026] [security2:error] [pid 11002:tid 11002] [client 91.219.237.39:14006] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pinebrookdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pinebrookdesign.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajtLdQ5PYiWPPp2boXDpggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack