๐ซ๐ฎ
mnazibo
2026-10-08 11:00:21
(1 minute ago)
Date: Oct 08 13:21:05 2026 EAT | Reported IP: 107.170.53.44 mod_security | id: 930130 949110 920340 ...
show more
Date: Oct 08 13:21:05 2026 EAT | Reported IP: 107.170.53.44 mod_security | id: 930130 949110 920340 920640 | US/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 5); Content-Type header missing from request with non-zero Content-Length; Content-Type header missing from request with non-zero Content-Length; Content-Type header missing from request with body; Content-Type header missing from request with body; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 10); Inbound Anomaly Score Exceeded (Total Score: 10); Inbound Anomaly Score Exceeded (Total Score: 5)
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ซ๐ท
masterguru
2026-10-08 10:57:29
(4 minutes ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ณ๐ฟ
Tripwire
2026-10-08 10:55:02
(6 minutes ago)
Scanning for exploits - /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
Web App Attack
๐ฉ๐ช
maxpower
2026-10-08 10:47:37
(14 minutes ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 107.170.53.44 (US/United States/-): 1 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 107.170.53.44 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 107.170.53.44 - - [08/Oct/2026:12:47:36 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/2.0" 200 4834 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36" "-" host=grafica-x.com
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 10:47:25
(14 minutes ago)
(mod_security) mod_security (id:210492) triggered by 107.170.53.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 107.170.53.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 06:47:18.824791 2026] [security2:error] [pid 12374:tid 12374] [client 107.170.53.44:17304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graficasbis.com"] [uri "/.env"] [unique_id "asd0tj8Qx9MylHduv4i46AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-10-08 10:44:12
(17 minutes ago)
CrowdSec crowdsecurity/CVE-2017-9841
Web App Attack
๐ซ๐ท
j-tap
2026-10-08 10:42:54
(18 minutes ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
๐ง๐ท
vfAcceloReporter
2026-10-08 10:42:36
(19 minutes ago)
107.170.53.44 - - [08/Oct/2026:07:42:35 -0300] "GET /.env HTTP/2.0" 502 559 "-" "Mozilla/5.0 (Window ...
show more
107.170.53.44 - - [08/Oct/2026:07:42:35 -0300] "GET /.env HTTP/2.0" 502 559 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Exploited Host
๐ธ๐ช
vaia.cloud
2026-10-08 10:40:01
(21 minutes ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐ฉ๐ช
Kitki30.com
2026-10-08 10:39:58
(21 minutes ago)
HTTP Probing (server 3). Log: 107.170.53.44 - - [08/Oct/2026:10:39:58 +0000] "GET /.env HTTP/1.1" 30 ...
show more
HTTP Probing (server 3). Log: 107.170.53.44 - - [08/Oct/2026:10:39:58 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
107.170.53.44 - - [08/Oct/2026:10:39:58 +0000] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Bonn333
2026-10-08 10:39:47
(21 minutes ago)
CrowdSec: suspicious activity detected by CrowdSec. Scenario=crowdsecurity/CVE-2017-9841; events=1; ...
show more
CrowdSec: suspicious activity detected by CrowdSec. Scenario=crowdsecurity/CVE-2017-9841; events=1; window=2026-10-08T10:39:45.891053644Z .. 2026-10-08T10:39:45.891053644Z. Tried: POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php. Automated report, no manual review.
show less
Hacking
๐ซ๐ท
polarolouis
2026-10-08 10:34:38
(27 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
๐ซ๐ท
Douglin
2026-10-08 10:30:56
(30 minutes ago)
Detectado pelo CrowdSec: crowdsecurity/CVE-2017-9841. Servidor de producao.
Brute-Force
SSH
Anonymous
2026-10-08 10:30:55
(30 minutes ago)
Scan for .git Files at 2026-10-08T10:30:55+00:00
Web App Attack
๐ซ๐ท
Eldeberen
2026-10-08 10:30:48
(30 minutes ago)
Vulnerability scan attempt through HTTP protocol
Web App Attack