๐ฉ๐ช
BiancaNL
2026-06-18 16:40:16
(13 hours ago)
Fail2Ban: jail=nginx-exploit-probes on <fqdn> (port=<port>)
Hacking
๐ท๐บ
DZBOT
2026-06-17 15:02:48
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 13:57:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 09:57:12.955398 2026] [security2:error] [pid 20711:tid 20711] [client 104.23.217.120:12387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bgraph.com"] [uri "/.git/config"] [unique_id "ajFWOFRnuM5UvBtgqCoeCAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 11:36:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 07:36:00.123790 2026] [security2:error] [pid 7796:tid 7796] [client 104.23.217.120:9594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carolinapetportraits.com"] [uri "/.git/config"] [unique_id "ajE1INrWbGQGYHu4EtBHhgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 07:44:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 03:44:34.270396 2026] [security2:error] [pid 26122:tid 26122] [client 104.23.217.120:12067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mariannehansen.com"] [uri "/.git/config"] [unique_id "ajD-4h5Zy1SDTUYiOr5A0AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 10:55:39
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 06:55:33.700063 2026] [security2:error] [pid 2395:tid 2395] [client 104.23.217.120:9656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlesicily.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "ai03JecxQ2fOc_pILg9dSgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-06-13 06:03:50
(6 days ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Ob ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 2 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
xxkodedxx
2026-06-13 00:28:09
(6 days ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 00:27:56 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php, /wp-admin/install.php?step=1
UA: "http://zvxlabs.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-11 03:12:41
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 23:39:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 19:39:06.772471 2026] [security2:error] [pid 21558:tid 21563] [client 104.23.217.120:13094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ramona.town"] [uri "/.env"] [unique_id "aidSmgqGecAUlQa44EOEjgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-06-05 15:18:06
(1 week ago)
Form spam
Web Spam
๐ฉ๐ช
Duggy_Tuxy๐งฑ
2026-06-03 03:26:04
(2 weeks ago)
[SW01-SRV01-DE] Banned by Fail2ban (Jail: syswarden-cms-honeypot)
Brute-Force
Hacking
๐ฉ๐ช
Duggy_Tuxy๐งฑ
2026-05-31 20:31:13
(2 weeks ago)
[SW01-SRV01-DE] Banned by Fail2ban (Jail: syswarden-cms-honeypot)
Brute-Force
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-25 05:59:44
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 01:59:36.293977 2026] [security2:error] [pid 19521:tid 19521] [client 104.23.217.120:11529] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "polarisled.com"] [uri "/.env.dev"] [unique_id "ahPlSFzh0ArmfLZiFYAY0wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-23 07:18:29
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack