๐ฌ๐ง
OptimusGO
2026-06-25 19:52:15
(6 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-25 20:52:14 UTC
Log evidence:
162.159.113.130 - - [25/Jun/2026:20:49:47 +0100] "GET /_phpinfo.php HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
162.159.113.130 - - [25/Jun/2026:20:52:14 +0100] "GET /docker/.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
06/25/2026-20:52:14.175690 [wDrop] [**] [1:1000110:2] SECURITY CRITICAL: .env File Access Attempt - INSTANT BAN [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 162.159.113.130:10580 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐ซ๐ท
omartin
2026-06-24 08:29:13
(1 day ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ด
jad-abuse
2026-06-23 23:50:09
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐ฉ๐ช
iNetWorker
2026-06-21 08:46:52
(4 days ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
mnsf
2026-06-19 21:05:12
(6 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-17 00:09:42
(1 week ago)
Abuse Detected (2)
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-06-16 17:08:59
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-06-14 06:07:03
(1 week ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 19:51:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.159.113.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.159.113.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 15:51:07.974097 2026] [security2:error] [pid 24633:tid 24633] [client 162.159.113.130:10923] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arteseros.com"] [uri "/.env.old"] [unique_id "ai20q8fp4khPUbleK1chswAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 19:20:36
(2 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 22:13:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.159.113.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.159.113.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:13:04.787612 2026] [security2:error] [pid 24193:tid 24193] [client 162.159.113.130:9795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indicadores.gabosoftware.com"] [uri "/.git/config"] [unique_id "aic-cIAfuiI_nLiQUBYYlgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 06:54:36
(3 weeks ago)
162.159.113.130 - - > tecnicman.com [02/Jun/2026:08:54:34 +0200] "POST /xmlrpc.php HTTP/2.0" 301 162 ...
show more
162.159.113.130 - - > tecnicman.com [02/Jun/2026:08:54:34 +0200] "POST /xmlrpc.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" "62.164.177.223"
162.159.113.130 - - > tecnicman.com [02/Jun/2026:08:54:35 +0200] "POST /xmlrpc.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0" "62.164.177.223"
162.159.113.130 - - > tecnicman.com [02/Jun/2026:08:54:35 +0200] "POST /blog/xmlrpc.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0" "62.164.177.223"
162.159.113.130 - - > tecnicman.com [02/Jun/2026:08:54:35 +0200] "POST /wp/xmlrpc.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" "62.164.177.223"
162.159.113.130 - - > tecnicma
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-29 22:06:13
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-28.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
COMPLEX
2026-05-29 00:31:58
(4 weeks ago)
Unsolicited TCP traffic | Action: DROP | Port 443
Phishing
๐บ๐ธ
TPI-Abuse
2026-05-28 09:28:52
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.159.113.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.159.113.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 05:27:56.391755 2026] [security2:error] [pid 6341:tid 6341] [client 162.159.113.130:9547] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wilhelminas.biz"] [uri "/.env.backup"] [unique_id "ahgKnAQuhhWk2fxVBASnTgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack