Anonymous
2026-07-30 20:21:17
(1 day ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-07-30 18:29:04
(1 day ago)
CrowdSec: HTTP technology/vendor fingerprint probing (reconnaissance scan) | req: /info.php | UA: Mo ...
show more
CrowdSec: HTTP technology/vendor fingerprint probing (reconnaissance scan) | req: /info.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.5 Safari/605.1.15
show less
Port Scan
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-30 18:28:57
(1 day ago)
cloudlinux2 fail2ban: 2026-07-30 20:23:52,613 fail2ban.filter [1584]: INFO [recidive] Fou ...
show more
cloudlinux2 fail2ban: 2026-07-30 20:23:52,613 fail2ban.filter [1584]: INFO [recidive] Found 149.40.58.28 - 2026-07-30 20:23:52cloudlinux2 fail2ban: 2026-07-30 20:23:52,605 fail2ban.actions [1584]: NOTICE [plesk-apache] Ban 149.40.58.28cloudlinux2 fail2ban: 2026-07-30 20:23:52,395 fail2ban.filter [1584]: INFO [plesk-apache] Found 149.40.58.28 - 2026-07-30 20:23:52cloudlinux2 fail2ban: 2026-07-30 20:24:00,352 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 173.239.211.207 - 2026-07-30 20:23:59cloudlinux2 fail2ban: 2026-07-30 20:25:50,674 fail2ban.actions [1584]: NOTICE [plesk-modsecurity] Unban 112.134.246.225cloudlinux2 fail2ban: 2026-07-30 20:26:51,523 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 112.134.246.225 - 2026-07-30 20:26:51cloudlinux2 fail2ban: 2026-07-30 20:28:02,864 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 167.253.16.26 - 2026-07-30 20:28:02cloudlinux2 fail2ban: 2026-07-30 20:28:04,884 fail2ban.filt
show less
Web App Attack
๐ฉ๐ช
findlab
2026-07-30 18:00:03
(1 day ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-30 17:18:46
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 28
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 17:08:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 13:08:02.568928 2026] [security2:error] [pid 900265:tid 900265] [client 160.176.144.54:51875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shhcenter.com"] [uri "/.env"] [unique_id "amuE8gtQ6m2S1_iYvCt65QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 16:52:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:52:49.305273 2026] [security2:error] [pid 3945430:tid 3945430] [client 160.176.144.54:55117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sheargrafix.com"] [uri "/.env"] [unique_id "amuBYYvT0N35K87qbV7HwwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 16:35:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:34:56.758399 2026] [security2:error] [pid 3070141:tid 3070141] [client 160.176.144.54:56617] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharawi-gum.com"] [uri "/.env"] [unique_id "amt9MK-v3mk7WB4YnDF9uQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-30 16:23:11
(1 day ago)
[ThuJul3018:23:08.4636012026][security2:error][pid3310980:tid3311493][client160.176.144.54:0]ModSecu ...
show more
[ThuJul3018:23:08.4636012026][security2:error][pid3310980:tid3311493][client160.176.144.54:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"shakary.com\"][uri\"/.env\"][unique_id\"amt6bIEDalOTnXeAWhD3nQAAAJg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 16:07:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:07:12.845224 2026] [security2:error] [pid 1685010:tid 1685010] [client 160.176.144.54:64732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seychelles-boat-registration.com"] [uri "/.env"] [unique_id "amt2sL-qLSm6EzBNcdl2KgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-30 15:45:41
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 15:42:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 160.176.144.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 11:42:44.105418 2026] [security2:error] [pid 2574061:tid 2574061] [client 160.176.144.54:64681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "serranoscoffee.com"] [uri "/.env"] [unique_id "amtw9B5FOHG0nAS1dXf-BwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-30 15:06:26
(1 day ago)
160.176.144.54 - - [30/Jul/2026:11:06:25 -0400] "GET /phpinfo.php HTTP/1.0" 302 450 "http://selfstor ...
show more
160.176.144.54 - - [30/Jul/2026:11:06:25 -0400] "GET /phpinfo.php HTTP/1.0" 302 450 "http://selfstorageofeasley.com/phpinfo.php" "Mozilla/5.0 (compatible; SemrushBot/7~bl; +http://www.semrush.com/bot.html)"
160.176.144.54 - - [30/Jul/2026:11:06:26 -0400] "GET /info.php HTTP/1.0" 302 444 "http://selfstorageofeasley.com/info.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0.0.0 Safari/537.36"
160.176.144.54 - - [30/Jul/2026:11:06:26 -0400] "GET /phpinfo.php HTTP/1.0" 500 5347 "http://www.selfstorageofeasley.com/phpinfo.php" "Mozilla/5.0 (compatible; SemrushBot/7~bl; +http://www.semrush.com/bot.html)"
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-07-30 07:35:36
(1 day ago)
371 requests with url.path /phpinfo.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
webanyone
2026-07-30 05:15:59
(1 day ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack