🇹🇷
oalver
2026-08-25 21:13:45
(2 weeks ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /blog/.env (HTTP 301). First seen: 2026-08-25. Risk score: 30/100.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 19:02:27
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 15:02:10.382115 2026] [security2:error] [pid 4098:tid 4098] [client 185.251.19.74:63585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.244"] [uri "/cgi-bin/.env"] [unique_id "ao3msqK6liqG7YjWoKJ_5QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
markawes
2026-08-25 14:23:36
(2 weeks ago)
[SynFast] Auto banned by Fail2Ban. Reason: Web vulnerability scan detected. Evidence:
185.251.19.74 ...
show more
[SynFast] Auto banned by Fail2Ban. Reason: Web vulnerability scan detected. Evidence:
185.251.19.74 - - [25/Aug/2026:14:23:29 +0000] "GET /admin/.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
185.251.19.74 - - [25/Aug/2026:14:23:35 +0000] "GET /base/.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
show less
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-08-25 13:04:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:04:14.266619 2026] [security2:error] [pid 8523:tid 8523] [client 185.251.19.74:48125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.30"] [uri "/crm/.env"] [unique_id "ao2SzpPeqnNe8oVitOqNnwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-08-25 13:01:09
(2 weeks ago)
Try to access /app/.env
Web App Attack
🇩🇪
Holger
2026-08-25 12:54:57
(2 weeks ago)
URL probing: GET /library/.env
Web App Attack
🇵🇱
Budyn
2026-08-22 02:49:01
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.space | URI: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-20 03:59:59
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-16 09:49:20
(3 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
LRob
2026-08-16 07:32:24
(3 weeks ago)
WordPress probing | req: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/5 ...
show more
WordPress probing | req: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36
show less
Brute-Force
Web App Attack
🇲🇹
Malta
2026-08-16 00:04:11
(3 weeks ago)
185.251.19.74 - - [16/Aug/2026:02:04:11 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
185.251.19.74 - - [16/Aug/2026:02:04:11 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇮🇹
CoreTech srl
2026-08-15 21:33:57
(3 weeks ago)
cloudlinux2 fail2ban: 2026-08-15 23:29:34,327 fail2ban.filter [1695]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-15 23:29:34,327 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 185.251.19.75 - 2026-08-15 23:29:33cloudlinux2 fail2ban: 2026-08-15 23:29:34,326 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 185.251.19.74 - 2026-08-15 23:29:33cloudlinux2 fail2ban: 2026-08-15 23:32:10,128 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 173.239.213.2 - 2026-08-15 23:32:09cloudlinux2 fail2ban: 2026-08-15 23:32:10,362 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 173.239.213.20 - 2026-08-15 23:32:09cloudlinux2 fail2ban: 2026-08-15 23:32:45,805 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 136.144.42.12 - 2026-08-15 23:32:45cloudlinux2 fail2ban: 2026-08-15 23:32:46,024 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 185.251.19.104 - 2026-08-15 23:32:45cloudlinux2 fail2ban: 2026-08-15 23:32:46,006 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 185.251.19.99 - 2026-08-15 23:32:45cloudli
show less
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-14 16:34:30
(3 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
Vianpyro
2026-08-13 11:23:09
(3 weeks ago)
Honeypot: 6 request(s) in 0 min. Paths: /api.json, /.git/config, /.gitconfig. Method(s): GET. UA: py ...
show more
Honeypot: 6 request(s) in 0 min. Paths: /api.json, /.git/config, /.gitconfig. Method(s): GET. UA: python-requests/2.34.2. ASN: 206092 (T.K Bytech LTD).
show less
Web App Attack
Bad Web Bot
Hacking
🇮🇹
VHosting
2026-08-12 15:15:03
(3 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack