๐ซ๐ท
โจ
2026-09-29 01:30:11
(4 hours ago)
Domain : andytather.com
Rule : env
2026-09-29 01:28:38 W3SVC12 PLESK76 217.194.212.5 GET /_profiler/ ...
show more
Domain : andytather.com
Rule : env
2026-09-29 01:28:38 W3SVC12 PLESK76 217.194.212.5 GET /_profiler/phpinfo.php - 443 - 116.6.233.229 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0 - - andytather.com 404 0 2 1605 155 242 - -
show less
Hacking
SQL Injection
๐ณ๐ฑ
Alt255
2026-09-28 21:34:39
(8 hours ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 116.6.233.229 - - [28/Sep/2026:23:34:36 +0200] "GET /_profiler/phpinfo.php HTTP/1.1" 301 716 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-09-28 20:21:21
(9 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-28 20:07:59
(9 hours ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
๐ช๐ธ
robotstxt
2026-09-28 19:38:05
(10 hours ago)
116.6.233.229 - - [28/Sep/2026:19:37:07 +0000] "GET /.env.save HTTP/1.1" 400 193 "-" "-" "-" edge="1 ...
show more
116.6.233.229 - - [28/Sep/2026:19:37:07 +0000] "GET /.env.save HTTP/1.1" 400 193 "-" "-" "-" edge="116.6.233.229"
116.6.233.229 - - [28/Sep/2026:19:37:08 +0000] "GET /beta/.env HTTP/1.1" 400 193 "-" "-" "-" edge="116.6.233.229"
116.6.233.229 - - [28/Sep/2026:19:37:09 +0000] "GET /admin/.env HTTP/1.1" 400 193 "-" "-" "-" edge="116.6.233.229"
116.6.233.229 - - [28/Sep/2026:19:37:10 +0000] "GET /app/.env HTTP/1.1" 400 193 "-" "-" "-" edge="116.6.233.229"
116.6.233.229 - - [28/Sep/2026:19:37:11 +0000] "GET /config/.env HTTP/1.1" 400 193 "-" "-" "-" edge="116.6.233.229"
...
show less
Web Spam
Web App Attack
๐ซ๐ท
dynamix
2026-09-28 17:42:43
(12 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-09-28 16:48:04
(13 hours ago)
Restricted File Access Attempt. Matched phrase "phpinfo.php" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-28 16:47:35
(13 hours ago)
116.6.233.229 - - [28/Sep/2026:12:47:18 -0400] "GET /_profiler/phpinfo.php HTTP/1.1" 404 50947 "-" " ...
show more
116.6.233.229 - - [28/Sep/2026:12:47:18 -0400] "GET /_profiler/phpinfo.php HTTP/1.1" 404 50947 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
116.6.233.229 - - [28/Sep/2026:12:47:31 -0400] "GET /phpinfo.php HTTP/1.1" 404 50947 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
116.6.233.229 - - [28/Sep/2026:12:47:34 -0400] "GET /info.php HTTP/1.1" 404 50947 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
...
show less
Web App Attack
Anonymous
2026-09-28 16:30:06
(13 hours ago)
| Multiple SQL injection attempts from same source ip.(multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
Petros Stefanakis
2026-09-28 16:10:07
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 116.6.233.229 (CN/China/-)
SQL Injection
๐ธ๐ช
vaia.cloud
2026-09-28 16:00:03
(14 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-09-28 15:54:47
(14 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.amli2018.com,www.amli2024.com; logs=/var/log/httpd/doma ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.amli2018.com,www.amli2024.com; logs=/var/log/httpd/domains/amli2018.com.log,/var/log/httpd/domains/amli2024.com.log; samples=/.env | /.env.production | /application/.env
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 14:07:38
(15 hours ago)
(mod_security) mod_security (id:210381) triggered by 2002:7406:e9e5::7406:e9e5 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210381) triggered by 2002:7406:e9e5::7406:e9e5 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 10:07:31.545741 2026] [security2:error] [pid 22368:tid 22368] [client 2002:7406:e9e5::7406:e9e5:54374] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||americanureport.com|F|4"] [data "REQUEST_URI=/cgi-bin/.%%%2%e/.%%%2%e/.%%%2%e/.%%%2%e/.%%%2%e/bin/sh"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "americanureport.com"] [uri "/cgi-bin/.%%%2%e/.%%%2%e/.%%%2%e/.%%%2%e/.%%%2%e/bin/sh"] [unique_id "arp0ox_wyK63aMoKpCU4wAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 13:32:12
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2002:7406:e9e5::7406:e9e5 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2002:7406:e9e5::7406:e9e5 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 09:32:03.865174 2026] [security2:error] [pid 10220:tid 10220] [client 2002:7406:e9e5::7406:e9e5:65258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americanexportimport.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "arpsUyncAcXzNk3kV2y-KwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 12:46:30
(17 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking