πΊπΈ
EvilTurkey
2026-09-30 12:22:49
(21 hours ago)
Web app attack against financial institution website.
Web App Attack
Hacking
π©πͺ
altenglaner
2026-09-30 09:52:10
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
π§πͺ
voormedia
2026-09-30 03:41:59
(1 day ago)
Accessed trap at '/.env'
Web App Attack
π©πͺ
LRob
2026-09-30 01:43:09
(1 day ago)
Secret file probe | method: GET | path: /.env | ua: curl/8.22.0
Hacking
Web App Attack
Anonymous
2026-09-30 00:06:57
(1 day ago)
Malicious scan detected (score: 5 >= 4): Path Matches Pattern (/.git/config, weight 5) on path: /.gi ...
show more
Malicious scan detected (score: 5 >= 4): Path Matches Pattern (/.git/config, weight 5) on path: /.git/config
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 10:50:01
(1 day ago)
suspicious request in access.log
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-29 09:10:50
(2 days ago)
[29/Sep/2026:12:10:50 +0300] -- 158.173.166.173 Ban reason: User-Agent curl/
Bad Web Bot
Web App Attack
π©πͺ
louis77
2026-09-29 07:21:01
(2 days ago)
Sensitive file access attempt - Path: /.env, Method: GET, UA: curl/8.22.0
Web App Attack
Hacking
π¨π
backslash
2026-09-29 06:06:00
(2 days ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
πΊπΈ
nationaleventpros.com
2026-09-29 01:07:58
(2 days ago)
vulnerability scan
Web App Attack
π«π·
arsonist
2026-09-29 00:10:19
(2 days ago)
[fail2ban]
2026-09-29T00:10:18.147819+00:00 arson caddy[1890453]: {"level":"info","ts":1790640618.14 ...
show more
[fail2ban]
2026-09-29T00:10:18.147819+00:00 arson caddy[1890453]: {"level":"info","ts":1790640618.1477945,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"158.173.166.173","remote_port":"65197","client_ip":"158.173.166.173","proto":"HTTP/1.1","method":"GET","host":"arson.gg","uri":"/.git/config","headers":{"User-Agent":["Go-http-client/1.1"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000098526,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"],"Access-Control-Allow-Origin":["*"]}}
...
show less
Bad Web Bot
πΏπ¦
conure.sh
2026-09-29 00:07:38
(2 days ago)
csagent: score 20.0: secrets grab x2, 404 noise floor x1; 1 domain(s) in 5s
Web App Attack
π³π±
Alt255
2026-09-27 00:10:18
(4 days ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 158.173.166.173 - - [27/Sep/2026:02:10:01 +0200] "GET /.git/config HTTP/1.1" 301 437 "-" "Go-http-client/1.1"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 17:45:12
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.166.173 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.166.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 13:45:06.040540 2026] [security2:error] [pid 30200:tid 30200] [client 158.173.166.173:21467] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||mjkhan.com|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "mjkhan.com"] [uri "/license.txt"] [unique_id "aixFos1ON5-nNUe7bVNXYwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 17:24:58
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.166.173 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.166.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 13:24:53.200803 2026] [security2:error] [pid 13972:tid 13972] [client 158.173.166.173:58899] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||pappakotis.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "pappakotis.net"] [uri "/license.txt"] [unique_id "aixA5fxu64UR6mdemlQwkAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack