Anonymous
2026-10-09 04:51:52
(11 minutes ago)
PAD: ModSec_Scanner!,ModSec_Critical detected
Hacking
๐ณ๐ฑ
bazter.pro
2026-10-09 04:14:47
(48 minutes ago)
185.220.249.158 - - [09/Oct/2026:04:14:46 +0000] "GET /.env HTTP/1.1" 404 293 "-" "Mozilla/5.0 (X11; ...
show more
185.220.249.158 - - [09/Oct/2026:04:14:46 +0000] "GET /.env HTTP/1.1" 404 293 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-10-09 04:03:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 185.220.249.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.220.249.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:03:11.309363 2026] [security2:error] [pid 5961:tid 5961] [client 185.220.249.158:65147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.71"] [uri "/.env"] [unique_id "ashnfya48HJTip7AjdaPwQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
regishoussin
2026-10-09 03:47:18
(1 hour ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-09 03:47 UTC.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hary74656
2026-10-09 03:13:40
(1 hour ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 185.220.249.158] [realclie ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 185.220.249.158] [realclient 185.220.249.158] [09/Oct/2026:05:13:40 +0200] [vhost schani.hostmi.at] 403 "GET /.env HTTP/1.1"
show less
Web App Attack
๐ซ๐ท
Kejult
2026-10-09 03:12:52
(1 hour ago)
Honeypot Finding: verified TCP multi-port scan/probing; 4 application-level events across 2 target p ...
show more
Honeypot Finding: verified TCP multi-port scan/probing; 4 application-level events across 2 target ports and 2 source port(s). Ports: 80/HTTP, 443/HTTPS. Sensors: H0neytr4p, Tanner.
show less
Port Scan
๐น๐ท
Domainhizmetleri.com
2026-10-09 02:55:13
(2 hours ago)
Source: DH Hunter (Honeypot) | Reason: HTTP Probe (80/tcp)
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 02:27:37
(2 hours ago)
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 185.220.249.158 - - [09/Oct/2026:04:27:16 +0200] "GET /.env HTTP/1.1" 404 7814 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:20:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.220.249.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.220.249.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:20:40.071344 2026] [security2:error] [pid 8277:tid 8277] [client 185.220.249.158:56806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.121"] [uri "/.env"] [unique_id "ashBaAdUBGgPlBl1oEtqggAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-10-09 00:37:50
(4 hours ago)
Blocked by UFW (TCP on 80)
Source port: 64537
TTL: 120
Packet length: 52
TOS: 0x02
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 64537
TTL: 120
Packet length: 52
TOS: 0x02
This report (for 185.220.249.158) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐ซ๐ท
โจ
2026-10-09 00:31:06
(4 hours ago)
Domain : redirect.netenergy.uk
Rule : env
2026-10-09 00:30:17 217.194.210.152 GET /17/.env - 443 - 1 ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-10-09 00:30:17 217.194.210.152 GET /17/.env - 443 - 185.220.249.158 HTTP/1.1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 - 217.194.210.152 404 0 2 1533 236 141 - -
show less
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-09 00:25:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.220.249.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.220.249.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:25:12.293921 2026] [security2:error] [pid 1052:tid 1052] [client 185.220.249.158:59637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.174"] [uri "/17/.env"] [unique_id "asg0aJtXvWmK7EWZ1WjpDgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
sonot
2026-10-08 04:42:18
(1 day ago)
Blocked by UFW on mail [8080/tcp] | SPT: 45686 | TTL: 237 | LEN: 40 | TOS: 0x00 โข Reported by: githu ...
show more
Blocked by UFW on mail [8080/tcp] | SPT: 45686 | TTL: 237 | LEN: 40 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-10-08 02:50:43
(1 day ago)
Unauthorized access (443/tcp/https)
Port Scan
Web App Attack
๐บ๐ธ
Tman111
2026-10-08 00:52:09
(1 day ago)
Unsolicited connection attempt to web ports (80/443). No service is offered to direct-to-IP traffic; ...
show more
Unsolicited connection attempt to web ports (80/443). No service is offered to direct-to-IP traffic; connection dropped. Scanner/bot behavior.
show less
Port Scan