๐ซ๐ท
Catalin Negru
2026-09-25 19:22:37
(2 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
Catalin Negru
2026-09-24 03:59:29
(3 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ณ๐ด
jad-abuse
2026-09-23 17:01:01
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup. Observed by 1 sensor(s); 21 hits.
show less
Web App Attack
๐ฎ๐ช
RoboSOC
2026-09-23 15:26:44
(4 days ago)
WordPress Core author exclude SQL Injection Vulnerability, PTR: pt1.webhop.net.
Hacking
๐ณ๐ฑ
debestelapp
2026-09-23 13:55:11
(4 days ago)
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-23 13:54:04
(4 days ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-23 07:38:24
(4 days ago)
[Wed Sep 23 17:38:23.905088 2026] [security2:error] [pid 327908] [client 176.61.146.167:64452] [clie ...
show more
[Wed Sep 23 17:38:23.905088 2026] [security2:error] [pid 327908] [client 176.61.146.167:64452] [client 176.61.146.167] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/"] [unique_id "arOB7ybEBC6rG7JPJe3j7gAAAB4"]
...
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-09-23 06:59:30
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.ovh | URI: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 | BODY: {"requests": []}
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-09-23 06:58:35
(4 days ago)
2026/09/23 06:58:33 [error] 1969705#1969705: *4474550 access forbidden by rule, client: 176.61.146.1 ...
show more
2026/09/23 06:58:33 [error] 1969705#1969705: *4474550 access forbidden by rule, client: 176.61.146.167, server: kocerroxy.com, request: "GET /.env.dist HTTP/1.1", host: "kocerroxy.com"
2026/09/23 06:58:34 [error] 1969705#1969705: *4474550 access forbidden by rule, client: 176.61.146.167, server: kocerroxy.com, request: "GET /.env.dist HTTP/1.1", host: "kocerroxy.com"
2026/09/23 06:58:34 [error] 1969705#1969705: *4474550 access forbidden by rule, client: 176.61.146.167, server: kocerroxy.com, request: "GET /.env.dev HTTP/1.1", host: "kocerroxy.com"
2026/09/23 06:58:34 [error] 1969705#1969705: *4474554 access forbidden by rule, client: 176.61.146.167, server: kocerroxy.com, request: "GET /.env.dev HTTP/1.1", host: "kocerroxy.com"
2026/09/23 06:58:34 [error] 1969705#1969705: *4474550 access forbidden by rule, client: 176.61.146.167, server: kocerroxy.com, request: "GET /.env.local HTTP/1.1", host: "kocerroxy.com"
...
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-23 01:35:53
(4 days ago)
[Wed Sep 23 11:35:52.017788 2026] [security2:error] [pid 321398] [client 176.61.146.167:53383] [clie ...
show more
[Wed Sep 23 11:35:52.017788 2026] [security2:error] [pid 321398] [client 176.61.146.167:53383] [client 176.61.146.167] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/"] [unique_id "arMs-Crx4MW_GzyoKhr_BQAAAA8"]
...
show less
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-23 01:31:42
(4 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-23 01:28:23
(4 days ago)
[redacted] 176.61.146.167 - - [23/Sep/2026:02:28:22 +0100] "GET /.[redacted] HTTP/1.1" 302 6763 0/73 ...
show more
[redacted] 176.61.146.167 - - [23/Sep/2026:02:28:22 +0100] "GET /.[redacted] HTTP/1.1" 302 6763 0/73016 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 443 [redacted] 176.61.146.167 - - [23/Sep/2026:02:28:22 +0100] "GET /.[redacted] HTTP/1.1" 302 1544 0/57634 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 23:27:28
(4 days ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 176.61.146.167 - - [23/Sep/2026:01:27:27 +0200] "GET /.env.bak HTTP/1.1" 301 501 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-22 21:14:31
(4 days ago)
SmallGuard.fr - HoneyPot
Web App Attack