🇳🇴
Abuse Buster
2026-09-11 01:40:18
(3 hours ago)
15.252.96.173 - - [11/Sep/2026:03:40:16 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macint ...
show more
15.252.96.173 - - [11/Sep/2026:03:40:16 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0"
15.252.96.173 - - [11/Sep/2026:03:40:17 +0200] "GET /.env HTTP/1.1" 404 22 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇧🇷
Peregrine
2026-09-10 03:09:20
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: - 15.252.96.173 - - [06/Sep/2026:15:16:57 -0300] "GET /.e ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: - 15.252.96.173 - - [06/Sep/2026:15:16:57 -0300] "GET /.env HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:16:58 -0300] "GET /.git/config HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:16:59 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:00 -0300] "GET /phpinfo.php HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:01 -0300] "GET /backup.sql HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:01 -0300] "GET /dump.sql HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:02 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:02 -0300] "GET /config.php.bak HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:03 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:04 -0300] "GET /backup.zip HTTP/1.1" 404 414
show less
Bad Web Bot
🇩🇪
konseptit
2026-09-09 22:06:29
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 15.252.96.173 (IN/India/ec2-15-252-96-1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 15.252.96.173 (IN/India/ec2-15-252-96-173.ap-south-1.compute.amazonaws.com)
show less
SQL Injection
🇫🇷
vincent_EUDIER
2026-09-09 13:20:00
(1 day ago)
GUEUDIER WEBAPP - HTTP 5xx Ban
Hacking
🇩🇪
Grossmann-Gruppe
2026-09-09 09:28:42
(1 day ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
Anonymous
2026-09-09 07:30:15
(1 day ago)
15.252.96.173 - - [09/Sep/2026:07:30:13 +0000] "GET /000000006aac436f-argus404probe HTTP/1.1" 404 16 ...
show more
15.252.96.173 - - [09/Sep/2026:07:30:13 +0000] "GET /000000006aac436f-argus404probe HTTP/1.1" 404 162 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:126.0) Gecko/20100101 Firefox/126.0"
15.252.96.173 - - [09/Sep/2026:07:30:14 +0000] "GET /.env HTTP/1.1" 404 162 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Web App Attack
🇫🇮
mnazibo
2026-09-09 02:00:10
(2 days ago)
Date: Sep 09 04:49:36 2026 EAT | Reported IP: 15.252.96.173 mod_security | id: 920350 930130 949110 ...
show more
Date: Sep 09 04:49:36 2026 EAT | Reported IP: 15.252.96.173 mod_security | id: 920350 930130 949110 920440 920500 | IN/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Host header is a numeric IP address; Host header is a numeric IP address; Host header is a numeric IP address; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 8); Host header is a numeric IP address; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 8); Host header is a numeric IP address; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 8); Host header is a numeric IP address; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 8); Host header is a numeric IP address; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 8); Host header is a numeric IP address; Host header is a numeric IP address; URL
show less
SQL Injection
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 21:54:12
(2 days ago)
Reported from Nginx log analysis 19. Log: 15.252.96.173 - - [08/Sep/2026:xx:xx:xx 0200] "GET / HTTP ...
show more
Reported from Nginx log analysis 19. Log: 15.252.96.173 - - [08/Sep/2026:xx:xx:xx 0200] "GET / HTTP/1.1" xxx xxx "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36" "-" "IN India Mumbai" "AS16509" "Amazon.com, Inc."
show less
Port Scan
Brute-Force
SSH
🇺🇸
hyena
2026-09-08 11:30:50
(2 days ago)
Repeated mod_security events.
Web App Attack
Anonymous
2026-09-08 06:38:36
(2 days ago)
HTTP_USER_AGENT Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0
Port Scan
🇧🇷
Peregrine
2026-09-08 03:09:30
(3 days ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: - 15.252.96.173 - - [06/Sep/2026:15:16:57 -0300] "GET /.e ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: - 15.252.96.173 - - [06/Sep/2026:15:16:57 -0300] "GET /.env HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:16:58 -0300] "GET /.git/config HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:16:59 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:00 -0300] "GET /phpinfo.php HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:01 -0300] "GET /backup.sql HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:01 -0300] "GET /dump.sql HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:02 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:02 -0300] "GET /config.php.bak HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:03 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:04 -0300] "GET /backup.zip HTTP/1.1" 404 414
show less
Bad Web Bot
🇩🇪
raph
2026-09-06 18:53:19
(4 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇧🇷
Peregrine
2026-09-06 18:17:07
(4 days ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: - 15.252.96.173 - - [06/Sep/2026:15:16:57 -0300] "GET /.e ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: - 15.252.96.173 - - [06/Sep/2026:15:16:57 -0300] "GET /.env HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:16:58 -0300] "GET /.git/config HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:16:59 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:00 -0300] "GET /phpinfo.php HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:01 -0300] "GET /backup.sql HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:01 -0300] "GET /dump.sql HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:02 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:02 -0300] "GET /config.php.bak HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:03 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 414
- 15.252.96.173 - - [06/Sep/2026:15:17:04 -0300] "GET /backup.zip HTTP/1.1" 404 414
show less
Bad Web Bot
🇩🇪
hidemail.app
2026-09-06 16:55:22
(4 days ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
🇫🇷
Baking333
2026-09-06 16:51:05
(4 days ago)
redacted:80 15.252.96.173 - - [06/Sep/2026:17:51:04 +0100] "GET /.env HTTP/1.1" 200 166 0/14520 "-" ...
show more
redacted:80 15.252.96.173 - - [06/Sep/2026:17:51:04 +0100] "GET /.env HTTP/1.1" 200 166 0/14520 "-" "Mozilla/5.0 (compatible; ArgusScanner/0.1; +http://example/abuse)" redacted:80 15.252.96.173 - - [06/Sep/2026:17:51:04 +0100] "GET /.git/config HTTP/1.1" 200 166 0/13594 "-" "Mozilla/5.0 (compatible; ArgusScanner/0.1; +http://example/abuse)"
show less
Bad Web Bot
Web App Attack