🇦🇷
181.166.175.99
21 seconds ago
(XMLRPC) WP XMLRPC Attack 181.166.175.99 (AR/Argentina/Buenos Aires/Lomas de Zamora/-/[AS7303 Teleco ...
show more
(XMLRPC) WP XMLRPC Attack 181.166.175.99 (AR/Argentina/Buenos Aires/Lomas de Zamora/-/[AS7303 Telecom Argentina S.A.]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 181.166.175.99 - - [17/Sep/2026:15:47:51 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18928 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/61.0.0.0 Safari/537.36"
show less
Port Scan
🇺🇸
193.37.33.85
23 seconds ago
(wplogin_block) Blocked WP-Login Access Attempt 193.37.33.85 (US/United States/Washington/Seattle/-/ ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 193.37.33.85 (US/United States/Washington/Seattle/-/[AS206092 F.n.s. Holdings Limited]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 193.37.33.85 - - [17/Sep/2026:15:40:55 +0300] "GET /wp-login.php HTTP/2.0" 404 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
show less
Port Scan
🇧🇷
186.238.210.226
6 minutes ago
186.238.210.226 (BR/Brazil/São Paulo/Bragança Paulista/-/[AS10429 TELEFONICA BRASIL S.A]), 2 distr ...
show more
186.238.210.226 (BR/Brazil/São Paulo/Bragança Paulista/-/[AS10429 TELEFONICA BRASIL S.A]), 2 distributed smtpauth attacks on account [[email protected] ] in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_DISTATTACK; Logs: 2026-09-17 15:48:06 dovecot_login authenticator failed for H=(h-46-59-108-174.A463.priv.bahnhof.se) [2.180.7.125]:60285: 535 Incorrect authentication data ([email protected] )
2026-09-17 11:57:49 dovecot_login authenticator failed for H=([196.191.212.235]) [186.238.210.226]:33369: 535 Incorrect authentication data ([email protected] )
IP Addresses Blocked:
2.180.7.125 (IR/Iran/-/-/-/[AS58224 Iran Telecommunication Company PJS])
show less
Port Scan
🇮🇷
2.180.7.125
6 minutes ago
(smtpauth) Failed SMTP AUTH login from 2.180.7.125 (IR/Iran/-/-/-/[AS58224 Iran Telecommunication Co ...
show more
(smtpauth) Failed SMTP AUTH login from 2.180.7.125 (IR/Iran/-/-/-/[AS58224 Iran Telecommunication Company PJS]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-17 15:48:06 dovecot_login authenticator failed for H=(h-46-59-108-174.A463.priv.bahnhof.se) [2.180.7.125]:60285: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇬🇧
165.154.128.199
9 minutes ago
(mod_security) mod_security (id:9999001) triggered by 165.154.128.199 (GB/United Kingdom/England/Cit ...
show more
(mod_security) mod_security (id:9999001) triggered by 165.154.128.199 (GB/United Kingdom/England/City of London/-/[AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 15:44:25.386300 2026] [security2:error] [pid 150930:tid 151032] [client 165.154.128.199:35588] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^154\\\\.57\\\\.7\\\\.73$" at REQUEST_HEADERS:Host. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "155"] [id "9999001"] [msg "Direct incoming request to server shared IP blocked by admin"] [hostname "154.57.7.73"] [uri "/"] [unique_id "aqvgqb6tM8Vq1MAd528UlQAABMo"]
show less
Port Scan
🇪🇹
102.213.70.99
12 minutes ago
(XMLRPC) WP XMLRPC Attack 102.213.70.99 (ET/Ethiopia/Addis Ababa/Addis Ababa/-/[AS328988 SAFARICOM T ...
show more
(XMLRPC) WP XMLRPC Attack 102.213.70.99 (ET/Ethiopia/Addis Ababa/Addis Ababa/-/[AS328988 SAFARICOM TELECOMMUNICATIONS ETHIOPIA PLC]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 102.213.70.99 - - [17/Sep/2026:15:39:18 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18938 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/94.0.0.0 Safari/537.36"
show less
Port Scan
🇺🇸
173.239.224.105
38 minutes ago
(mod_security) mod_security (id:1000001) triggered by 173.239.224.105 (US/United States/Texas/Dallas ...
show more
(mod_security) mod_security (id:1000001) triggered by 173.239.224.105 (US/United States/Texas/Dallas/-/[AS396356 Latitude.sh]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 15:15:50.810324 2026] [security2:error] [pid 150579:tid 150606] [remote 173.239.224.105:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp-content/admin.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/admin.php"] [severity "CRITICAL"] [tag "security"] [hostname "santoriniicon.com"] [uri "/wp-content/admin.php"] [unique_id "aqvZ9lCDju6va6J-S_-f0wACAwY"], referer: https://santoriniicon.com/
show less
Port Scan
🇩🇪
91.107.209.60
41 minutes ago
(mod_security) mod_security (id:11000011) triggered by 91.107.209.60 (DE/Germany/Saxony/Falkenstein/ ...
show more
(mod_security) mod_security (id:11000011) triggered by 91.107.209.60 (DE/Germany/Saxony/Falkenstein/-/[AS24940 Hetzner Online GmbH]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 15:12:34.213930 2026] [security2:error] [pid 151048:tid 151093] [client 91.107.209.60:44670] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "clients.your-server.de" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: static.60.209.107.91.clients.your-server.de"] [severity "CRITICAL"] [hostname "ftiaxtomonosou.gr"] [uri "/"] [unique_id "aqvZMlF_OtpL9nCyxqnkSgAAAEc"]
show less
Port Scan
🇺🇸
185.170.167.18
43 minutes ago
(mod_security) mod_security (id:11000010) triggered by 185.170.167.18 (GB/United Kingdom/-/-/-/[AS20 ...
show more
(mod_security) mod_security (id:11000010) triggered by 185.170.167.18 (GB/United Kingdom/-/-/-/[AS209366 SEMrush CY LTD]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 15:10:47.931495 2026] [security2:error] [pid 151443:tid 151579] [client 185.170.167.18:12388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "BacklinksExtendedBot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "114"] [id "11000010"] [msg "BLOCKED BOT: BacklinksExtendedBot on ns2.setworldup365.com"] [severity "ALERT"] [hostname "ns2.setworldup365.com"] [uri "/robots.txt"] [unique_id "aqvYxwFuN4pU-VU-m6yFpQAABIc"]
show less
Port Scan
🇸🇪
176.10.202.13
43 minutes ago
(smtpauth) Failed SMTP AUTH login from 176.10.202.13 (SE/Sweden/Värmland County/Karlstad/-/[AS8473 ...
show more
(smtpauth) Failed SMTP AUTH login from 176.10.202.13 (SE/Sweden/Värmland County/Karlstad/-/[AS8473 Bahnhof AB]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-17 15:10:37 dovecot_login authenticator failed for H=h-176-10-202-13.a463.priv.bahnhof.se ([121.46.239.203]) [176.10.202.13]:42412: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇺🇸
152.233.42.203
51 minutes ago
(mod_security) mod_security (id:11000011) triggered by 152.233.42.203 (US/United States/Virginia/Ash ...
show more
(mod_security) mod_security (id:11000011) triggered by 152.233.42.203 (US/United States/Virginia/Ashburn/-/[AS60068 Datacamp Limited]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 15:03:00.311745 2026] [security2:error] [pid 151048:tid 151093] [client 152.233.42.203:48710] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "datapacket.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: unn-152-233-42-203.datapacket.com"] [severity "CRITICAL"] [hostname "cpanagiotou.gr"] [uri "/"] [unique_id "aqvW9FF_OtpL9nCyxqnkPAAAAEc"]
show less
Port Scan
🇺🇸
20.118.219.100
56 minutes ago
(mod_security) mod_security (id:9999001) triggered by 20.118.219.100 (US/United States/Iowa/Des Moin ...
show more
(mod_security) mod_security (id:9999001) triggered by 20.118.219.100 (US/United States/Iowa/Des Moines/-/[AS8075 Microsoft Corporation]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:58:20.715532 2026] [security2:error] [pid 151443:tid 151555] [client 20.118.219.100:39734] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^154\\\\.57\\\\.7\\\\.73$" at REQUEST_HEADERS:Host. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "155"] [id "9999001"] [msg "Direct incoming request to server shared IP blocked by admin"] [hostname "154.57.7.73"] [uri "/developmentserver/metadatauploader"] [unique_id "aqvV3AFuN4pU-VU-m6yCwQAABIA"]
show less
Port Scan
🇺🇸
3.208.156.9
1 hour ago
(mod_security) mod_security (id:11000010) triggered by 3.208.156.9 (US/United States/Virginia/Ashbur ...
show more
(mod_security) mod_security (id:11000010) triggered by 3.208.156.9 (US/United States/Virginia/Ashburn/-/[AS14618 Amazon.com, Inc.]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:54:15.592932 2026] [security2:error] [pid 150930:tid 151035] [client 3.208.156.9:28483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Amazonbot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "114"] [id "11000010"] [msg "BLOCKED BOT: Amazonbot on cpanagiotou.gr"] [severity "ALERT"] [hostname "cpanagiotou.gr"] [uri "/en/constructions_en/apartment-building-in-galatsi/"] [unique_id "aqvU576tM8Vq1MAd528QlAAABM0"]
show less
Port Scan
🇺🇸
52.2.58.41
1 hour ago
(mod_security) mod_security (id:11000010) triggered by 52.2.58.41 (US/United States/Virginia/Ashburn ...
show more
(mod_security) mod_security (id:11000010) triggered by 52.2.58.41 (US/United States/Virginia/Ashburn/-/[AS14618 Amazon.com, Inc.]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:52:34.526026 2026] [security2:error] [pid 151072:tid 151246] [client 52.2.58.41:7133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Amazonbot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "114"] [id "11000010"] [msg "BLOCKED BOT: Amazonbot on babis.photo"] [severity "ALERT"] [hostname "babis.photo"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "aqvUgoTBJCfkePg114t2fAAAANU"]
show less
Port Scan
🇺🇸
68.227.77.67
1 hour ago
(smtpauth) Failed SMTP AUTH login from 68.227.77.67 (US/United States/Arkansas/Johnson/-/[AS22773 Co ...
show more
(smtpauth) Failed SMTP AUTH login from 68.227.77.67 (US/United States/Arkansas/Johnson/-/[AS22773 Cox Communications Inc.]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-17 14:50:57 dovecot_login authenticator failed for H=wsip-68-227-77-67.fv.ks.cox.net (nsg-corporate-130.221.187.122.airtel.in) [68.227.77.67]:48738: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇮🇳
182.95.226.138
1 hour ago
182.95.226.138 (IN/India/National Capital Territory of Delhi/New Delhi/-/[AS9498 BHARTI Airtel Ltd.] ...
show more
182.95.226.138 (IN/India/National Capital Territory of Delhi/New Delhi/-/[AS9498 BHARTI Airtel Ltd.]), 2 distributed smtpauth attacks on account [[email protected] ] in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_DISTATTACK; Logs: 2026-09-17 08:24:35 dovecot_login authenticator failed for H=(nsg-static-211.62.71.182.airtel.in) [182.95.226.138]:37414: 535 Incorrect authentication data ([email protected] )
2026-09-17 14:44:11 dovecot_login authenticator failed for H=([59.28.170.183]) [218.233.182.39]:14573: 535 Incorrect authentication data ([email protected] )
IP Addresses Blocked:
show less
Port Scan
🇰🇷
218.233.182.39
1 hour ago
(smtpauth) Failed SMTP AUTH login from 218.233.182.39 (KR/South Korea/Gyeongsangbuk-do/Gumi/-/[AS931 ...
show more
(smtpauth) Failed SMTP AUTH login from 218.233.182.39 (KR/South Korea/Gyeongsangbuk-do/Gumi/-/[AS9318 SK Broadband Co Ltd]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-17 14:44:11 dovecot_login authenticator failed for H=([59.28.170.183]) [218.233.182.39]:14573: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇵🇱
217.182.73.60
1 hour ago
(mod_security) mod_security (id:11000011) triggered by 217.182.73.60 (FR/France/-/-/-/[AS16276 OVH S ...
show more
(mod_security) mod_security (id:11000011) triggered by 217.182.73.60 (FR/France/-/-/-/[AS16276 OVH SAS]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:41:31.037132 2026] [security2:error] [pid 151072:tid 151251] [client 217.182.73.60:57156] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "ovh.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: vps-c7769941.vps.ovh.net"] [severity "CRITICAL"] [hostname "ftiaxtomonosou.gr"] [uri "/wp-content/uploads/2019/07/%CE%9F%CE%B9%CE%BA%CE%AF%CE%B1-%CE%A0%CF%81%CE%AD%CF%83%CE%B2%CE%B7-%CE%99%CE%B1%CF%80%CF%89%CE%BD%CE%AF%CE%B1%CF%82_28.jpg"] [unique_id "aqvR64TBJCfkePg114t2bAAAANY"]
show less
Port Scan
🇫🇷
51.91.255.78
1 hour ago
(mod_security) mod_security (id:11000011) triggered by 51.91.255.78 (FR/France/-/-/-/[AS16276 OVH SA ...
show more
(mod_security) mod_security (id:11000011) triggered by 51.91.255.78 (FR/France/-/-/-/[AS16276 OVH SAS]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:41:33.264364 2026] [security2:error] [pid 151072:tid 151210] [client 51.91.255.78:34830] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "ovh.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: vps-dd125ed6.vps.ovh.net"] [severity "CRITICAL"] [hostname "ftiaxtomonosou.gr"] [uri "/wp-content/uploads/2019/07/%CE%9F%CE%B9%CE%BA%CE%AF%CE%B1-%CE%A0%CF%81%CE%AD%CF%83%CE%B2%CE%B7-%CE%99%CE%B1%CF%80%CF%89%CE%BD%CE%AF%CE%B1%CF%82_28.jpg"] [unique_id "aqvR7YTBJCfkePg114t2bQAAAMw"]
show less
Port Scan
🇧🇪
34.79.174.58
1 hour ago
(mod_security) mod_security (id:11000011) triggered by 34.79.174.58 (BE/Belgium/Brussels Capital/Bru ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.79.174.58 (BE/Belgium/Brussels Capital/Brussels/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:28:00.704551 2026] [security2:error] [pid 151048:tid 151100] [client 34.79.174.58:50922] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 58.174.79.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "www.ftiaxtomonosou.gr"] [uri "/"] [unique_id "aqvOwFF_OtpL9nCyxqneyAAAAEk"]
show less
Port Scan
🇮🇳
4.224.45.129
1 hour ago
(mod_security) mod_security (id:1000001) triggered by 4.224.45.129 (IN/India/Maharashtra/Pune/-/[AS8 ...
show more
(mod_security) mod_security (id:1000001) triggered by 4.224.45.129 (IN/India/Maharashtra/Pune/-/[AS8075 Microsoft Corporation]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:27:22.559690 2026] [security2:error] [pid 150820:tid 150907] [remote 4.224.45.129:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/1.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /1.php"] [severity "CRITICAL"] [tag "security"] [hostname "www.endoscope.center"] [uri "/1.php"] [unique_id "aqvOmqRiby8Hf2zPUkkSZwACTBg"]
show less
Port Scan
🇺🇸
136.67.125.137
1 hour ago
(mod_security) mod_security (id:11000011) triggered by 136.67.125.137 (US/United States/Oregon/The D ...
show more
(mod_security) mod_security (id:11000011) triggered by 136.67.125.137 (US/United States/Oregon/The Dalles/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:21:30.675810 2026] [security2:error] [pid 150820:tid 150921] [client 136.67.125.137:62990] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 137.125.67.136.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "fashionfragonard.gr"] [uri "/"] [unique_id "aqvNOqRiby8Hf2zPUkkSMAAAAkA"]
show less
Port Scan
🇧🇷
16.5.0.172
1 hour ago
(mod_security) mod_security (id:9999001) triggered by 16.5.0.172 (BR/Brazil/São Paulo/São Paulo/-/ ...
show more
(mod_security) mod_security (id:9999001) triggered by 16.5.0.172 (BR/Brazil/São Paulo/São Paulo/-/[AS401661 AS401661]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:20:53.337334 2026] [security2:error] [pid 151048:tid 151151] [client 16.5.0.172:40517] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^154\\\\.57\\\\.7\\\\.73$" at REQUEST_HEADERS:Host. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "155"] [id "9999001"] [msg "Direct incoming request to server shared IP blocked by admin"] [hostname "154.57.7.73"] [uri "/"] [unique_id "aqvNFVF_OtpL9nCyxqneqQAAAFU"]
show less
Port Scan
🇺🇸
173.239.224.104
1 hour ago
(mod_security) mod_security (id:1000001) triggered by 173.239.224.104 (US/United States/Texas/Dallas ...
show more
(mod_security) mod_security (id:1000001) triggered by 173.239.224.104 (US/United States/Texas/Dallas/-/[AS396356 Latitude.sh]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:18:26.623209 2026] [security2:error] [pid 150820:tid 150907] [remote 173.239.224.104:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp-content/admin.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /admin.php/wp-content/admin.php"] [severity "CRITICAL"] [tag "security"] [hostname "www.santoriniicon.com"] [uri "/admin.php/wp-content/admin.php"] [unique_id "aqvMgqRiby8Hf2zPUkkR_wACRBg"], referer: https://www.santoriniicon.com/admin.php
show less
Port Scan
🇺🇸
173.239.224.95
1 hour ago
(mod_security) mod_security (id:1000001) triggered by 173.239.224.95 (US/United States/Texas/Dallas/ ...
show more
(mod_security) mod_security (id:1000001) triggered by 173.239.224.95 (US/United States/Texas/Dallas/-/[AS396356 Latitude.sh]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 14:18:26.109103 2026] [security2:error] [pid 151283:tid 151337] [remote 173.239.224.95:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp-content/admin.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /admin.php/wp-content/admin.php"] [severity "CRITICAL"] [tag "security"] [hostname "santoriniicon.com"] [uri "/admin.php/wp-content/admin.php"] [unique_id "aqvMgtjUopyh6wx7XouqkgADCAg"], referer: https://santoriniicon.com/admin.php
show less
Port Scan