๐ซ๐ท
Catalin Negru
2026-08-21 12:04:15
(4 days ago)
2026-08-07 12:10:55,503 fail2ban.actions [722]: NOTICE [apache-scan] Ban 104.131.176.217
202 ...
show more
2026-08-07 12:10:55,503 fail2ban.actions [722]: NOTICE [apache-scan] Ban 104.131.176.217
2026-08-07 12:10:55,550 fail2ban.actions [722]: NOTICE [apache-404] Ban 104.131.176.217
2026-08-07 12:10:56,718 fail2ban.actions [722]: NOTICE [web-scanner] Ban 104.131.176.217
2026-08-07 12:10:57,283 fail2ban.actions [722]: NOTICE [apache-security] Ban 104.131.176.217
2026-08-07 12:10:57,618 fail2ban.actions [722]: NOTICE [laravel-auth] Ban 104.131.176.217
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-16 02:08:01
(1 week ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,ice02,wa01,wa02]
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-16 01:07:02
(1 week ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [mx02]
Bad Web Bot
Web App Attack
๐บ๐ธ
its101
2026-08-09 06:05:06
(2 weeks ago)
Automated detection by LockdownAccess security system. Attack type(s): env_grab, framework_probe, co ...
show more
Automated detection by LockdownAccess security system. Attack type(s): env_grab, framework_probe, config_probe. Reason: Nginx: env_grab attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Web App Attack
Anonymous
2026-08-09 05:55:03
(2 weeks ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1, GET /humans.txt HTTP/1.1, GET /.e ...
show more
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1, GET /humans.txt HTTP/1.1, GET /.env.prod HTTP/1.1, GET /cookies HTTP/1.1, GET /terraform.tfvars HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-08-09 05:05:12
(2 weeks ago)
Too many Status 40X (11)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-09 04:24:18
(2 weeks ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
๐บ๐ธ
WellSpring
2026-08-09 04:17:47
(2 weeks ago)
env leak on careenough.us/backend/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐จ๐ฆ
danieljamesbertrand
2026-08-09 04:17:22
(2 weeks ago)
fail2ban jail=nginx-access-exploit on canadapaywall.com (automatic report; categories 19,21)
Bad Web Bot
Web App Attack
๐ซ๐ฎ
pixiekat
2026-08-09 03:44:24
(2 weeks ago)
[Sun Aug 09 04:44:22.276052 2026] [authz_core:error] [pid 993025:tid 993076] [client 104.131.176.217 ...
show more
[Sun Aug 09 04:44:22.276052 2026] [authz_core:error] [pid 993025:tid 993076] [client 104.131.176.217:58498] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/webkitten-net/web/.env
[Sun Aug 09 04:44:23.757263 2026] [authz_core:error] [pid 993102:tid 993137] [client 104.131.176.217:54252] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/webkitten-net/web/.netrc
[Sun Aug 09 04:44:23.787007 2026] [authz_core:error] [pid 993025:tid 993088] [client 104.131.176.217:54476] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/webkitten-net/web/.env.prod
[Sun Aug 09 04:44:23.787840 2026] [authz_core:error] [pid 993102:tid 993143] [client 104.131.176.217:54456] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/webkitten-net/web/.env.old
[Sun Aug 09 04:44:23.790552 2026] [authz_core:error] [pid 993025:tid 993089] [client 104.131.176.217:54416] AH01630: client denied by server conf
...
show less
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-08-09 01:44:52
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ง๐ช
cmbplf
2026-08-09 01:05:46
(2 weeks ago)
2.230 requests from abuseipdb.com blacklisted IP (4mos2w6d)
Brute-Force
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-09 00:43:18
(2 weeks ago)
2026/08/09 01:43:16 [error] 57176#57176: *196065 access forbidden by rule, client: 104.131.176.217, ...
show more
2026/08/09 01:43:16 [error] 57176#57176: *196065 access forbidden by rule, client: 104.131.176.217, server: bestasquadradas.org, request: "GET /wp/.env HTTP/2.0", host: "bestasquadradas.org"
2026/08/09 01:43:16 [error] 57178#57178: *196068 access forbidden by rule, client: 104.131.176.217, server: bestasquadradas.org, request: "GET /backend/.env HTTP/2.0", host: "bestasquadradas.org"
2026/08/09 01:43:16 [error] 57180#57180: *196070 access forbidden by rule, client: 104.131.176.217, server: bestasquadradas.org, request: "GET /public/.env HTTP/2.0", host: "bestasquadradas.org"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Hary74656
2026-08-09 00:40:53
(2 weeks ago)
[Sun Aug 09 02:40:42.451437 2026] [security2:error] [pid 217310:tid 217479] [client 104.131.176.217: ...
show more
[Sun Aug 09 02:40:42.451437 2026] [security2:error] [pid 217310:tid 217479] [client 104.131.176.217:34514] [client 104.131.176.217] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "aschi.at"] [uri "/.git/config"] [unique_id "anfMikV6Ic3BZmoNJwpSCgAAAtI"], referer: http://aschi.at/.git/config
[Sun Aug 09 02:40:42.479541 2026] [security2:error] [pid 216991:tid 217141] [client 104.131.176.217:34748] [client 104.131.176.217] ModSecurity: Access denied with code 403 (phase 2). String match
...
show less
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-08-09 00:06:40
(2 weeks ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /.git/head | Pays: US | UA: Mozilla/5.0 (compatible; Per ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /.git/head | Pays: US | UA: Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
show less
Hacking
Web App Attack