๐ฆ๐น
joe-abuse
2026-06-21 01:33:01
(4 hours ago)
Automated report from fail2ban on www.fitzgerald.eu. Jail: recidive. First seen: 2026-06-20 07:00:08 ...
show more
Automated report from fail2ban on www.fitzgerald.eu. Jail: recidive. First seen: 2026-06-20 07:00:08. Events: 9. Reported by ipdb-security/fitzgerald.eu
show less
Email Spam
Brute-Force
๐ณ๐ฑ
Savvii
2026-06-20 18:59:43
(11 hours ago)
20 attempts against mh-misbehave-ban on star
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-06-20 18:22:03
(11 hours ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/HEAD Se ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/HEAD Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ธ๐ฌ
Starburst SysOp Team
2026-06-20 15:49:35
(14 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-sin2-2)
Hacking
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-06-20 15:12:06
(14 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐ฉ๐ช
dpsbs
2026-06-20 14:09:53
(15 hours ago)
url scanning on multiple public ips detected
Bad Web Bot
๐ฉ๐ช
Mykola Spesivtsev
2026-06-20 11:25:51
(18 hours ago)
HTTP Tarpit detected bot activity:TargetPort:443, Path:/, Method:GET, UA:Mozilla/5.0 (Macintosh; Int ...
show more
HTTP Tarpit detected bot activity:TargetPort:443, Path:/, Method:GET, UA:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.
show less
Port Scan
Web App Attack
Bad Web Bot
๐ธ๐ช
KIDOS
2026-06-20 11:16:06
(18 hours ago)
CrowdSec detected malicious activity
DDoS Attack
๐บ๐ธ
Void Vendor
2026-06-20 11:04:43
(19 hours ago)
VoidTrap [15,21]: [offense #1 โ 30 minutes] Honeypot: /api/v1/login | ip: 141.98.252.235 | loc: Lond ...
show more
VoidTrap [15,21]: [offense #1 โ 30 minutes] Honeypot: /api/v1/login | ip: 141.98.252.235 | loc: London, England, GB, AS39351 31173 Services AB | path: /api/v1/login | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
show less
Hacking
Web App Attack
๐ธ๐ช
Johan Finn
2026-06-20 10:16:04
(19 hours ago)
malicious activity
Web App Attack
๐ฆ๐บ
aranguren.org
2026-06-20 10:13:29
(19 hours ago)
141.98.252.235 - - [20/Jun/2026:20:13:28 +1000] "GET /.env HTTP/2.0" 404 985 "-" "Mozilla/5.0 (Windo ...
show more
141.98.252.235 - - [20/Jun/2026:20:13:28 +1000] "GET /.env HTTP/2.0" 404 985 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36 Edg/101.0.1210.47"
141.98.252.235 - - [20/Jun/2026:20:13:28 +1000] "GET /.env.backup HTTP/2.0" 404 985 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36 Edg/101.0.1210.47"
141.98.252.235 - - [20/Jun/2026:20:13:28 +1000] "GET /.env.old HTTP/2.0" 404 985 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36 Edg/101.0.1210.47"
141.98.252.235 - - [20/Jun/2026:20:13:28 +1000] "GET /api/.env HTTP/2.0" 404 985 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36 Edg/101.0.1210.47"
141.98.252.235 - - [20/Jun/2026:20:13:28 +1000] "GET /.env.production HTTP/2.0" 404 985 "-" "Mozilla/5.0 (Windows NT
...
show less
Bad Web Bot
๐ง๐ท
SOC PR
2026-06-20 09:04:10
(21 hours ago)
IPS: Web Server Exposed Git Repository Information Disclosure.
Hacking
๐ณ๐ด
jad-abuse
2026-06-20 08:14:48
(21 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe. Observed by 1 sensor(s); 90 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 07:21:46
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.98.252.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.98.252.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 03:21:42.689287 2026] [security2:error] [pid 23424:tid 23424] [client 141.98.252.235:53732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.190"] [uri "/.env.dev"] [unique_id "ajY_hrHj8DWTwsOR-A9pAwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-06-12 08:00:51
(1 week ago)
Brute force
Brute-Force