π©πͺ
Vegascosmetics
2026-07-16 13:32:43
(1 week ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after suspicious activity. Vegas Security
DDoS Attack
Hacking
Exploited Host
π¬π§
openstrike.co.uk
2026-06-30 05:14:04
(4 weeks ago)
4 attacks on env grabbing URLs, PHP URLs:
GET /.env HTTP/1.1
GET /fckeditor/editor/filemanager/conne ...
show more
4 attacks on env grabbing URLs, PHP URLs:
GET /.env HTTP/1.1
GET /fckeditor/editor/filemanager/connectors/php/upload.php?Type=Media HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
Lee Daniel
2026-06-29 09:27:40
(4 weeks ago)
92.241.37.243 - - [29/Jun/2026:05:27:24 -0400] "GET /administrator HTTP/1.1" 404 20365 "-" "Mozilla/ ...
show more
92.241.37.243 - - [29/Jun/2026:05:27:24 -0400] "GET /administrator HTTP/1.1" 404 20365 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
92.241.37.243 - - [29/Jun/2026:05:27:31 -0400] "GET /sites/all/libraries/mailchimp/vendor/phpunit/phpunit/build.xml HTTP/1.1" 404 20682 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50"
92.241.37.243 - - [29/Jun/2026:05:27:33 -0400] "GET /sites/all/libraries/php-curl-class/vendor/phpunit/phpunit/build.xml HTTP/1.1" 404 20697 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50"
92.241.37.243 - - [29/Jun/2026:05:27:36 -0400] "GET /vuln.htm HTTP/1.1" 404 20520 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
92.241.37.243 - - [29/Jun/2026:05:27:39 -0400] "GET /vuln.htm HTTP/1.1" 404 20520 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Ge
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-06-29 05:07:01
(4 weeks ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,mx01,mx02]
Bad Web Bot
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-06-29 04:09:01
(4 weeks ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [mx03,wa01,wa02]
Bad Web Bot
Web App Attack
π¬π§
gurnip
2026-06-29 02:56:36
(4 weeks ago)
Vulnerability probe of page /wp-includes/js/jquery/jquery.js, not found on server.
Brute-Force
Web App Attack
π¬π§
Apache
2026-06-29 00:41:32
(4 weeks ago)
(mod_security) mod_security (id:933110) triggered by 92.241.37.243 (JO/Jordan/-): 5 in the last 300 ...
show more
(mod_security) mod_security (id:933110) triggered by 92.241.37.243 (JO/Jordan/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
π«π·
β¨
2026-06-29 00:24:20
(4 weeks ago)
Domain : boylecontracts.co.uk
Rule : admin
2026-06-29 00:13:25 W3SVC465 PLESK72 79.171.34.94 GET /ad ...
show more
Domain : boylecontracts.co.uk
Rule : admin
2026-06-29 00:13:25 W3SVC465 PLESK72 79.171.34.94 GET /administrator/help/en-GB/toc.json - 80 - 92.241.37.243 HTTP/1.1 Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0 - - boylecontracts.co.uk 404 0 2 1536 236 76 - -
show less
Hacking
SQL Injection
Brute-Force
π¬π§
Greg Poulson
2026-06-28 14:15:07
(1 month ago)
Our website was hit by this DDOS at a rate of 29 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
π¬π§
consul.to
2026-06-28 04:35:57
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-27 19:33:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 92.241.37.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 92.241.37.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 15:33:11.431786 2026] [security2:error] [pid 14629:tid 14648] [client 92.241.37.243:51600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furball.co.uk"] [uri "/.env"] [unique_id "akAld66ARdeDsjFlm3Z1TAAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-06-27 17:29:44
(1 month ago)
Probing websites for vulnerabilities
Web App Attack
π¬π§
AvonleaConsulting
2026-06-27 13:35:02
(1 month ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
π¬π§
Mendip_Defender
2026-06-27 11:49:37
(1 month ago)
92.241.37.243 - - [27/Jun/2026:12:48:39 +0100] "GET /?page=wysija_campaigns&action=themes HTTP/1.1" ...
show more
92.241.37.243 - - [27/Jun/2026:12:48:39 +0100] "GET /?page=wysija_campaigns&action=themes HTTP/1.1" 301 5736 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
92.241.37.243 - - [27/Jun/2026:12:48:39 +0100] "GET /?page=wysija_campaigns&action=themes HTTP/1.1" 404 50947 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
92.241.37.243 - - [27/Jun/2026:12:49:28 +0100] "GET /?action=getcountryuser&cs=2 HTTP/1.1" 301 5655 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-27 10:44:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 92.241.37.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 92.241.37.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 06:44:13.026081 2026] [security2:error] [pid 20122:tid 20122] [client 92.241.37.243:64341] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oxford-gliding-club.co.uk"] [uri "/.env"] [unique_id "aj-pfW_83RrfLC9YEyilsQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack