๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 22:01:32
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-09-16 22:01:23
(3 days ago)
Auto-ban: >3000 req/min op 2026-09-16
Web App Attack
SSH
Hacking
๐ญ๐บ
miszterx.hu
2026-09-16 08:41:42
(4 days ago)
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐บ๐ธ
MPL
2026-09-16 04:25:35
(4 days ago)
tcp ports: 80,443 (12 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-16 03:08:36
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 15.206.25.71 (ec2-15-206-25-71.ap-south-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 15.206.25.71 (ec2-15-206-25-71.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:08:29.881889 2026] [security2:error] [pid 4195:tid 4195] [client 15.206.25.71:49962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kbalan.com"] [uri "/wp-config.php.bak"] [unique_id "aqoILaeZiJu0gZ5djZ6znAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-16 01:26:01
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: apm.teddypot.cloud | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-16 01:02:18
(4 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:34:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 15.206.25.71 (ec2-15-206-25-71.ap-south-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 15.206.25.71 (ec2-15-206-25-71.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:34:54.454749 2026] [security2:error] [pid 3816:tid 3816] [client 15.206.25.71:38870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starsmogsandiego.com"] [uri "/.env.old"] [unique_id "aqnkLsE9hTWSThul0jLnTgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-09-16 00:11:38
(4 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฆ๐บ
Bay13
2026-09-15 23:28:44
(4 days ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-15 23:24:33
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-15 20:59:42
(5 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 15.206.25.71 (IN/India/ec2-15-206-2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 15.206.25.71 (IN/India/ec2-15-206-25-71.ap-south-1.compute.amazonaws.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:42:24
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 15.206.25.71 (ec2-15-206-25-71.ap-south-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 15.206.25.71 (ec2-15-206-25-71.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:42:20.036775 2026] [security2:error] [pid 12399:tid 12420] [client 15.206.25.71:47836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "testproperty.pref-realestate.com"] [uri "/wp-config.php.bak"] [unique_id "aqmtrDWNNfK8yjUo47J-6wAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:15:01
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 15.206.25.71 (ec2-15-206-25-71.ap-south-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 15.206.25.71 (ec2-15-206-25-71.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:14:56.323640 2026] [security2:error] [pid 28326:tid 28326] [client 15.206.25.71:60280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thrudheim.org"] [uri "/.env.txt"] [unique_id "aqmnQFKVlQoml0viFmXxwgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
FireGuard Server
2026-09-15 19:35:04
(5 days ago)
Blocked by os-abuseipdb; 7 hits, proto=tcp, ports=443
Port Scan
Hacking