🇲🇾
Rizzy
2026-08-07 07:19:07
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇩🇪
macrob
2026-08-05 11:58:39
(1 month ago)
2026/08/05 11:58:35 [error] 2674674#2674674: *448260006 access forbidden by rule, client: 185.158.10 ...
show more
2026/08/05 11:58:35 [error] 2674674#2674674: *448260006 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua"
2026/08/05 11:58:36 [error] 2674675#2674675: *448212056 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua/wp-login.php?action=register"
2026/08/05 11:58:37 [error] 2674674#2674674: *448289838 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua/wp-login.php?action=register"
...
show less
Web App Attack
🇲🇾
Rizzy
2026-08-02 16:19:53
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇦🇺
paulshipley.com.au
2026-08-01 20:25:26
(1 month ago)
[Sun Aug 02 06:25:25.627712 2026] [security2:error] [pid 843834] [client 185.158.106.218:45534] [cli ...
show more
[Sun Aug 02 06:25:25.627712 2026] [security2:error] [pid 843834] [client 185.158.106.218:45534] [client 185.158.106.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/xmlrpc.php"] [unique_id "am5WNZc54a5UJPRsk-U7GQAAAAY"], referer: https://paulshipley.com.au/xmlrpc.php?rsd
...
show less
Web App Attack
🇩🇪
macrob
2026-08-01 19:08:51
(1 month ago)
2026/08/01 19:08:45 [error] 82069#82069: *435982830 access forbidden by rule, client: 185.158.106.21 ...
show more
2026/08/01 19:08:45 [error] 82069#82069: *435982830 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua"
2026/08/01 19:08:46 [error] 82069#82069: *435982858 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua/wp-login.php?action=register"
2026/08/01 19:08:50 [error] 82071#82071: *435982604 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua/wp-login.php?action=register"
...
show less
Web App Attack
🇦🇺
paulshipley.com.au
2026-07-27 23:47:36
(1 month ago)
[Tue Jul 28 09:47:35.174278 2026] [security2:error] [pid 178338] [client 185.158.106.218:57311] [cli ...
show more
[Tue Jul 28 09:47:35.174278 2026] [security2:error] [pid 178338] [client 185.158.106.218:57311] [client 185.158.106.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/xmlrpc.php"] [unique_id "amfuF6G42p19TKVCfxC0VgAAAAI"], referer: https://paulshipley.com.au/xmlrpc.php?rsd
...
show less
Web App Attack
🇩🇪
macrob
2026-07-26 00:55:16
(1 month ago)
2026/07/26 00:55:10 [error] 2642818#2642818: *411663648 access forbidden by rule, client: 185.158.10 ...
show more
2026/07/26 00:55:10 [error] 2642818#2642818: *411663648 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua"
2026/07/26 00:55:13 [error] 2642819#2642819: *411667565 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua/wp-login.php?action=register"
2026/07/26 00:55:14 [error] 2642820#2642820: *411667531 access forbidden by rule, client: 185.158.106.218, server: fastcredit.net.ua, request: "GET /wp-login.php?action=register HTTP/2.0", host: "fastcredit.net.ua", referrer: "https://fastcredit.net.ua/wp-login.php?action=register"
...
show less
Web App Attack
🇲🇾
Rizzy
2026-07-25 20:52:45
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇩🇪
big-cloud.nl
2026-07-25 14:21:45
(1 month ago)
Try to access /xmlrpc.php
Web App Attack
🇺🇸
ipblock.com
2026-07-24 11:55:00
(1 month ago)
IPBlock protected site ID [4055-d][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-07-24 04:06:25
(1 month ago)
[FriJul2406:06:18.5731492026][security2:error][pid1759895:tid1760200][client185.158.106.218:0]ModSec ...
show more
[FriJul2406:06:18.5731492026][security2:error][pid1759895:tid1760200][client185.158.106.218:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"www.vetreriaperletti.ch\"][uri\"/xmlrpc.php\"][unique_id\"amLkuhyb9qlJLWF6GNB8egAAAQ4\"]\,referer:https://www.vetreriaperletti.ch/
show less
Hacking
Web App Attack
🇺🇸
ipblock.com
2026-07-22 07:47:00
(1 month ago)
IPBlock protected site ID [4055-d][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-07-20 23:37:00
(1 month ago)
IPBlock protected site ID [4055-d][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-07-18 12:46:29
(1 month ago)
Try to access /xmlrpc.php
Web App Attack
🇦🇺
paulshipley.com.au
2026-07-17 16:10:02
(1 month ago)
[Sat Jul 18 02:10:01.571668 2026] [security2:error] [pid 663355] [client 185.158.106.218:48313] [cli ...
show more
[Sat Jul 18 02:10:01.571668 2026] [security2:error] [pid 663355] [client 185.158.106.218:48313] [client 185.158.106.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/xmlrpc.php"] [unique_id "alpT2fQlAUs2Svu6JZbs_wAAAAw"], referer: https://paulshipley.com.au/xmlrpc.php?rsd
...
show less
Web App Attack