๐ฉ๐ช
LRob.fr
2026-06-05 13:30:04
(1 week ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-30 09:10:32
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ณ๐ฟ
Antinson
2026-05-20 23:24:25
(3 weeks ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
threatintelligence_bvc
2026-05-17 04:05:50
(4 weeks ago)
Brute-Force
๐ฉ๐ช
AetherFox
2026-05-15 23:13:02
(1 month ago)
AetherFox VoidGuard detected: [Fri May 15 23:13:01.656989 2026] [authz_core:error] [pid 4135065:tid ...
show more
AetherFox VoidGuard detected: [Fri May 15 23:13:01.656989 2026] [authz_core:error] [pid 4135065:tid 4135068] [client 185.251.19.18:33937] AH01630: client denied by server configuration: proxy:http://[MASKED]/wp-admin/css/colors/
[Fri May 15 23:13:01.657124 2026] [authz_core:error] [pid 4135065:tid 4135068] [client 185.251.19.18:33937] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Fri May 15 23:13:01.838216 2026] [authz_core:error] [pid 4135065:tid 4135098] [client 185.251.19.18:33937] AH01630: client denied by server configuration: proxy:http://[MASKED]/wp-includes/css/dist/customize-widgets/
[Fri May 15 23:13:01.838290 2026] [authz_core:error] [pid 4135065:tid 4135098] [client 185.251.19.18:33937] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Fri May 15 23:13:02.006791 2026] [authz_core:error] [pid 4135065:tid 4135082] [client 185.251.19.18:33937] AH01630: client denied by server config
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-15 18:05:31
(1 month ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ท๐ธ
Smel
2026-03-18 04:07:10
(2 months ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
๐บ๐ธ
threatintelligence_bvc
2026-03-15 21:21:42
(3 months ago)
Brute-Force
๐ซ๐ฎ
gnom4ik
2026-02-27 20:31:13
(3 months ago)
ban-reviewer auto report; ip=185.251.19.18; scenario=http:scan; verdict=valid_ban; confidence=0.92; ...
show more
ban-reviewer auto report; ip=185.251.19.18; scenario=http:scan; verdict=valid_ban; confidence=0.92; categories=14,15,18,22; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high
show less
Port Scan
Hacking
Brute-Force
SSH
๐จ๐ญ
Origon
2026-02-26 05:27:30
(3 months ago)
recidive - IP: 185.251.19.18 - 2026-02-20 13:26:09,324 fail2ban.actions [245081]: NOTICE [plesk-wor ...
show more
recidive - IP: 185.251.19.18 - 2026-02-20 13:26:09,324 fail2ban.actions [245081]: NOTICE [plesk-wordpress] Ban 185.251.19.18 2026-02-20 14:37:09,453 fail2ban.actions [245081]: NOTICE [plesk-wordpress] Ban 185.251.19.18 2026-02-20 15:12:35,706 fail2ban.actions [245081]: NOTICE [plesk-wordpress] Ban 185.251.19.18
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-02-21 01:40:41
(3 months ago)
10 attempts against mh-misc-ban on twig
Web App Attack
๐บ๐ธ
WeekendWeb
2026-02-20 17:28:58
(3 months ago)
Wordpress Vunerability attack
Web App Attack
๐จ๐ญ
Origon
2026-02-20 14:12:36
(3 months ago)
recidive - IP: 185.251.19.18 - 2026-02-20 13:26:09,324 fail2ban.actions [245081]: NOTICE [plesk-wor ...
show more
recidive - IP: 185.251.19.18 - 2026-02-20 13:26:09,324 fail2ban.actions [245081]: NOTICE [plesk-wordpress] Ban 185.251.19.18 2026-02-20 14:37:09,453 fail2ban.actions [245081]: NOTICE [plesk-wordpress] Ban 185.251.19.18 2026-02-20 15:12:35,706 fail2ban.actions [245081]: NOTICE [plesk-wordpress] Ban 185.251.19.18
show less
Web App Attack
๐จ๐ฆ
KIsmay
2026-02-20 12:46:34
(3 months ago)
Feb 20 07:46:30 www4 WPAudit[1211616]: 185.251.19.18 www.nelsonbcwelding.com "Mozilla/5.0 (Windows N ...
show more
Feb 20 07:46:30 www4 WPAudit[1211616]: 185.251.19.18 www.nelsonbcwelding.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" sbd-admin:Sbd-admin123123 FAIL
Feb 20 07:46:31 www4 WPAudit[1211616]: 185.251.19.18 www.nelsonbcwelding.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" sbd-admin:Sbd-admin123321 FAIL
Feb 20 07:46:32 www4 WPAudit[1211616]: 185.251.19.18 www.nelsonbcwelding.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" sbd-admin:Sbd-admin1234 FAIL
Feb 20 07:46:33 www4 WPAudit[1211616]: 185.251.19.18 www.nelsonbcwelding.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" sbd-admin:Sbd-admin12345 FAIL
Feb 20 07:46:34 www4 WPAudit[1211616]: 185.251.19.18 www.nelsonbcwelding.com "Mozilla/5.0 (Windows
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 06:26:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 01:26:13.016629 2026] [security2:error] [pid 20530:tid 20530] [client 185.251.19.18:46743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.180"] [uri "/audio/.env"] [unique_id "aZatBaGLariTrDS3mNA7OgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack