๐ฉ๐ช
zumbo.net
2026-08-24 01:56:40
(5 days ago)
[Mon Aug 24 04:56:39.363121 2026] [proxy_fcgi:error] [pid 986242:tid 986263] [client 15.223.179.227: ...
show more
[Mon Aug 24 04:56:39.363121 2026] [proxy_fcgi:error] [pid 986242:tid 986263] [client 15.223.179.227:0] AH01071: Got error 'Primary script unknown'
[Mon Aug 24 04:56:39.480154 2026] [proxy_fcgi:error] [pid 986244:tid 986252] [client 15.223.179.227:0] AH01071: Got error 'Primary script unknown'
[Mon Aug 24 04:56:39.607027 2026] [proxy_fcgi:error] [pid 986242:tid 986285] [client 15.223.179.227:0] AH01071: Got error 'Primary script unknown'
[Mon Aug 24 04:56:39.723877 2026] [proxy_fcgi:error] [pid 986244:tid 986256] [client 15.223.179.227:0] AH01071: Got error 'Primary script unknown'
[Mon Aug 24 04:56:39.839629 2026] [proxy_fcgi:error] [pid 986244:tid 986260] [client 15.223.179.227:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-08-24 01:01:33
(5 days ago)
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Director ...
show more
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Directory Brute-Forcing / Content Discovery, Predictable Resource Location / Forced Browsing, Scan for administration and debugging interfaces of modern frameworks, Scan for Spring Boot Actuator Leaks, Scan for Cloud & Infrastructure Credentials, Scan for Database & Backup Dumps, Scan for IDE- und Editor-Configurations, Scan for CI/CD Pipelines & GitHub Workflows etc. The Attacker is permanently banned by Fail2Ban, configurate by JKweb Security a brand of JKweb Service.
show less
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-23 21:59:21
(5 days ago)
Auto-ban: >3000 req/min op 2026-08-23
Web App Attack
SSH
Hacking
๐ง๐ช
cmbplf
2026-08-23 21:43:38
(5 days ago)
647 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
RamSet
2026-08-23 15:59:39
(5 days ago)
[ycr] HTTP-Probe on port 443 (via domain). 34 distinct paths probed in 10s. Sustained 34 req/min, 34 ...
show more
[ycr] HTTP-Probe on port 443 (via domain). 34 distinct paths probed in 10s. Sustained 34 req/min, 34 nonexistent paths (404). Paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging, /.env.development, /.env.test, /.env.remote, /.env.bak, /.env.backup, /.env.save, /.env.old, /.env.sample, /.env.example, /.env.dev, /.env.prod, /.env.stage, /.env.ci, /.env.docker, /.env.live, /.env.preprod, /.env.uat, /.env.dist, /.env.swp, /.env.txt, /.env.json, /.env.yaml, /.env.yml, /app/.env, /apps/.env, /.env1, /.env2, /.env_copy, /.env~
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-08-23 14:07:21
(5 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-08-23T14:07:19.256592536Z. Context: http_status=200
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-23 09:41:26
(6 days ago)
Excessive 404/403 errors
Brute-Force
๐จ๐ญ
๐จ๐ญ Hosting
2026-08-23 05:10:21
(6 days ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 15:51:01
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 15.223.179.227 (ec2-15-223-179-227.ca-central-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 15.223.179.227 (ec2-15-223-179-227.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:50:53.084572 2026] [security2:error] [pid 11203:tid 11203] [client 15.223.179.227:59302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.purlandpurr.leadek.com"] [uri "/.git/config"] [unique_id "aonFXVkXNIx9auH_oi59BwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-22 15:00:47
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-22 13:46:43
(6 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-22 10:05:15
(1 week ago)
Too many Status 40X (13)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 02:30:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 15.223.179.227 (ec2-15-223-179-227.ca-central-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 15.223.179.227 (ec2-15-223-179-227.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 22:30:46.023947 2026] [security2:error] [pid 21408:tid 21408] [client 15.223.179.227:32916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pumps.aguasolar.com"] [uri "/.git/config"] [unique_id "aokJ1u5eEXN2XkfxjB6omQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-21 14:09:05
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ช
Mr-Money
2025-11-16 22:41:14
(9 months ago)
scenario: crowdsecurity/http-sensitive-files - events: 5
Hacking
Web App Attack