๐น๐ท
Domainhizmetleri.com
2026-09-14 15:37:48
(3 days ago)
Source: DH Hunter (Honeypot) | Reason: Portscan (1 ports, 2 attempts in 480h)
Port Scan
๐บ๐ธ
MPL
2026-09-13 21:39:43
(3 days ago)
tcp port scan (16 or more attempts)
Port Scan
๐ง๐ท
dermatovirtual
2026-09-13 18:44:08
(4 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 121 unauthorized requests recorded between 2026-09-12 18:41:35 UTC and 2026-09-12 18:42:03 UTC (rate: ~121 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-12 18:42:00 UTC] IP: 104.199.220.139 - W3C IIS (Port 80): GET /actuator/mappings -> HTTP 500 [CLIENT: 104.199.220.139]
[2026-09-12 18:42:00 UTC] IP: 104.199.220.139 - W3C IIS (Port 80): GET /actuator/httptrace -> HTTP 500 [CLIENT: 104.199.220.139]
[2026-09-12 18:42:03 UTC] IP: 104.199.220.139 - W3C IIS (Port 80): GET /.env.copy -> HTTP 500 [CLIENT: 104.199.220.139]
show less
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-13 13:39:05
(4 days ago)
blocked for webapp attack | path requested: / | seen at 2026-09-13 13:38:27.750 |
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 12:49:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.220.139 (139.220.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.220.139 (139.220.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:49:53.619400 2026] [security2:error] [pid 8841:tid 8841] [client 104.199.220.139:5134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.137"] [uri "/media../.env"] [unique_id "aqab8Rk23Oit77gihyPrkAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-09-13 11:52:56
(4 days ago)
Blocked by UFW (TCP on 8443)
Source port: 62576
TTL: 61
Packet length: 60
TOS: 0x00
This report (fo ...
show more
Blocked by UFW (TCP on 8443)
Source port: 62576
TTL: 61
Packet length: 60
TOS: 0x00
This report (for 104.199.220.139) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-09-13 10:30:47
(4 days ago)
automatically banned
Brute-Force
Web App Attack
๐ญ๐ฐ
ncsr-sec
2026-09-13 05:37:04
(4 days ago)
Attacked NCSR.CN production server: SSH brute-force / web scanning / honeypot trips. fail2ban banned ...
show more
Attacked NCSR.CN production server: SSH brute-force / web scanning / honeypot trips. fail2ban banned. Evidence in server logs.
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-12 21:46:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.220.139 (139.220.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.220.139 (139.220.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:46:36.660192 2026] [security2:error] [pid 27872:tid 27872] [client 104.199.220.139:27612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.158"] [uri "/static../.env"] [unique_id "aqXIPKVeccgEmZIdxGJ85QAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
oisecnet
2026-09-12 21:01:41
(4 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-12. 296 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-12. 296 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
MPL
2026-09-12 19:44:37
(4 days ago)
tcp port scan (16 or more attempts)
Port Scan
๐ง๐ท
dermatovirtual
2026-09-12 18:43:23
(5 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 115 unauthorized requests recorded between 2026-09-12 18:41:35 UTC and 2026-09-12 18:41:57 UTC (rate: ~115 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-12 18:41:47 UTC] IP: 104.199.220.139 - W3C IIS (Port 80): GET /.env.test -> HTTP 500 [CLIENT: 104.199.220.139]
[2026-09-12 18:41:50 UTC] IP: 104.199.220.139 - W3C IIS (Port 80): GET /aws/.env -> HTTP 500 [CLIENT: 104.199.220.139]
[2026-09-12 18:41:50 UTC] IP: 104.199.220.139 - W3C IIS (Port 80): GET /aws/.env.production -> HTTP 500 [CLIENT: 104.199.220.139]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 14:16:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.220.139 (139.220.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.220.139 (139.220.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 10:16:30.139199 2026] [security2:error] [pid 10607:tid 10607] [client 104.199.220.139:34050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.61"] [uri "/static../.env"] [unique_id "aqVevkhiDnWPqRHNv5fBPwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 12:04:54
(5 days ago)
Date: 2026/09/12 21 04 54
URI: http://121.184.2.116:8000/.env
Web App Attack
๐ธ๐ช
KIDOS
2026-09-12 06:24:46
(5 days ago)
KASM auto: exploit_/.env.local
Brute-Force
SSH