๐ฉ๐ช
Philister11
2026-09-24 01:36:29
(1 hour ago)
CrowdSec: crowdsecurity/http-cve-probing (US/AS142430)
Web App Attack
Hacking
๐ฉ๐ช
Philister11
2026-09-24 00:18:45
(2 hours ago)
CrowdSec: LePresidente/http-generic-403-bf (US/AS142430)
Web App Attack
Brute-Force
๐น๐ท
neron
2026-09-23 23:38:37
(2 hours ago)
CrowdSec blocked: ssh:bruteforce detected via OPNsense firewall
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-09-23 23:23:34
(3 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: billing.astropot.store | URI: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
teknoshop
2026-09-23 19:16:17
(7 hours ago)
Automated honeypot/rate-limit ban on teknoshopmarket.it: Honeypot endpoint: /wordpress/wp-json/batch ...
show more
Automated honeypot/rate-limit ban on teknoshopmarket.it: Honeypot endpoint: /wordpress/wp-json/batch/v1
show less
Port Scan
Bad Web Bot
Web App Attack
๐ฎ๐น
ipald
2026-09-23 19:06:20
(7 hours ago)
MIoT SecOps: Web probe: wordpress-probe
Web App Attack
๐บ๐ธ
MatCat
2026-09-23 18:05:07
(8 hours ago)
Banned by fail2ban: apache-noscript
Hacking
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-23 17:35:58
(9 hours ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /wp/v2/posts/999999. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tmiland
2026-09-23 17:07:30
(9 hours ago)
Detected 101 connections from 103.168.67.253 last 10 minutes.; lone high-rate source (combined 202 r ...
show more
Detected 101 connections from 103.168.67.253 last 10 minutes.; lone high-rate source (combined 202 requests in both windows); Logs: 103.168.67.253 - - [23/Sep/2026:19:06:48 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 405 552 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 103.168.67.253 - - [23/Sep/2026:19:06:48 +0200] "POST /index.php?rest_route=/batch/v1 HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 103.168.67.253 - - [23/Sep/2026:19:06:48 +0200] "POST /index.php?rest_route=%2Fbatch%2Fv1 HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 103.168.67.253 - - [23/Sep/2026:19:06:48 +0200] "POST /?rest_route=%2Fbatch%2Fv1 HTTP/1.1" 405 552 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safa
show less
DDoS Attack
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tmiland
2026-09-23 17:06:59
(9 hours ago)
(nginx_404s) Nginx Security rule triggered from 103.168.67.253 (US/United States/253.67.168.103.in-a ...
show more
(nginx_404s) Nginx Security rule triggered from 103.168.67.253 (US/United States/253.67.168.103.in-addr.arpa.digivps.com): 50 in the last 3600 secs; IP: 103.168.67.253; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/09/23 19:06:48 [error] 2138692#2138692: *4857 open() "/home/abuseip/public_html/wp-json/batch/v1" failed (2: No such file or directory), client: 103.168.67.253, server: abuseip.cc, request: "POST /wp-json/batch/v1 HTTP/1.1", host: "mail.abuseip.cc" 2026/09/23 19:06:49 [error] 2138692#2138692: *4857 open() "/home/abuseip/public_html/wp-json/Batch/v1" failed (2: No such file or directory), client: 103.168.67.253, server: abuseip.cc, request: "POST /wp-json/Batch/v1 HTTP/1.1", host: "mail.abuseip.cc" 2026/09/23 19:06:49 [error] 2138692#2138692: *4857 open() "/home/abuseip/public_html/wp-json/batch/v1" failed (2: No such file or directory), client: 103.168.67.253, server: abuseip.cc, request: "POST //wp-json/batch/v1 HTTP/1.1", host: "mail.abuseip.cc" 2026/09/23 19:06:49 [error] 213
show less
Brute-Force
๐ฉ๐ช
Hary74656
2026-09-23 16:46:10
(9 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-404, failures=30.
[earlier text truncated]
3.168.67.253] [ ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-404, failures=30.
[earlier text truncated]
3.168.67.253] [realclient 103.168.67.253] - - [23/Sep/2026:18:46:00 +0200] [vhost linkhub.aschi.at] "POST /wp-json/batch/v1/ HTTP/1.1" 404 470 "https://linkhub.aschi.at/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
[client 103.168.67.253] [realclient 103.168.67.253] - - [23/Sep/2026:18:46:09 +0200] [vhost linkhub.aschi.at] "POST /blog/wp-json/batch/v1 HTTP/1.1" 404 5497 "https://linkhub.aschi.at/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
[client 103.168.67.253] [realclient 103.168.67.253] - - [23/Sep/2026:18:46:09 +0200] [vhost linkhub.aschi.at] "POST /wordpress/wp-json/batch/v1 HTTP/1.1" 404 470 "https://linkhub.aschi.at/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
Omega Threat-ID
2026-09-23 15:46:07
(10 hours ago)
Omega Point Threat ID honeypot sensor observed: honeypot, abuse-reported, otx-flagged
Port Scan
๐จ๐ฆ
zXero
2026-09-23 12:42:06
(13 hours ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
๐ฉ๐ช
webanyone
2026-09-23 07:33:03
(19 hours ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-23 07:06:11
(19 hours ago)
Excessive multi-domain requests
Brute-Force