π³π±
homeshowdomain.nl
2026-10-02 21:59:11
(10 hours ago)
Auto-ban: >3000 req/min op 2026-10-02
Web App Attack
SSH
Hacking
Anonymous
2026-10-02 19:11:55
(13 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: MA, Attack patterns: Clou ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: MA, Attack patterns: Cloud secrets probing
show less
Bad Web Bot
Web App Attack
π«π·
arsonist
2026-10-02 14:30:22
(18 hours ago)
[fail2ban]
2026-10-02T14:30:21.820489+00:00 arson caddy[1712]: {"level":"info","ts":1790951421.82046 ...
show more
[fail2ban]
2026-10-02T14:30:21.820489+00:00 arson caddy[1712]: {"level":"info","ts":1790951421.820464,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"105.158.169.238","remote_port":"47530","client_ip":"105.158.169.238","proto":"HTTP/1.1","method":"GET","host":"ntfy.arson.gg","uri":"/.env","headers":{"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"ntfy.arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000060404,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
π©πͺ
dbmwebdesign
2026-10-02 14:25:09
(18 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
π΅π±
sefinek.net
2026-10-02 14:16:36
(18 hours ago)
Triggered Cloudflare WAF (firewallCustom) from MA.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from MA.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env | UA: Empty string β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-02 14:06:12
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 105.158.169.238 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 105.158.169.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:06:05.191270 2026] [security2:error] [pid 31826:tid 31826] [client 105.158.169.238:36472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virtualvideo.org"] [uri "/.env"] [unique_id "ar-6TWEoUpKJZcoZgzZJTQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-10-02 13:36:24
(19 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 09:18:18
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 105.158.169.238 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 105.158.169.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:18:11.308329 2026] [security2:error] [pid 13905:tid 13905] [client 105.158.169.238:48742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mspish2.com"] [uri "/.env"] [unique_id "ar9209KA8dCseASPdo6QdQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 09:18:04
(23 hours ago)
Web application attack detected.
Web App Attack
Anonymous
2026-10-02 09:10:36
(23 hours ago)
PSCSERV WPSCAN 105.158.169.238
Bad Web Bot
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-10-02 09:08:00
(23 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-10-02 08:05:35
(1 day ago)
csagent: score 20.3: secrets grab x2, 404 noise floor x2; 1 domain(s) in 4s
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-02 08:01:18
(1 day ago)
[02/Oct/2026:11:01:17 +0300] -- 105.158.169.238 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[02/Oct/2026:11:01:17 +0300] -- 105.158.169.238 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
π«π·
arsonist
2026-10-02 07:54:57
(1 day ago)
[fail2ban]
2026-10-02T07:54:57.204985+00:00 arson caddy[1890453]: {"level":"info","ts":1790927697.20 ...
show more
[fail2ban]
2026-10-02T07:54:57.204985+00:00 arson caddy[1890453]: {"level":"info","ts":1790927697.2049544,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"105.158.169.238","remote_port":"58488","client_ip":"105.158.169.238","proto":"HTTP/1.1","method":"GET","host":"git.arson.gg","uri":"/.env","headers":{"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"git.arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000078849,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
π©πͺ
pltcldvlpr
2026-10-02 07:53:54
(1 day ago)
CMS/framework probe: 105.158.169.238 - - [02/Oct/2026:09:53:53 +0200] "GET /.env HTTP/1.1" 400 141 " ...
show more
CMS/framework probe: 105.158.169.238 - - [02/Oct/2026:09:53:53 +0200] "GET /.env HTTP/1.1" 400 141 "-" "-" asn=36903 org="Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM" country=MA
...
show less
Web App Attack