πΉπ·
oalver
2026-10-08 16:04:06
(47 seconds ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_rate_flood ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_rate_flood, nginx_404_flood, nginx_path_signature. Sources: nginx. Details: path_signature: request to /.git/config (HTTP 404); 404_flood: 10 requests to /media../.git/config (HTTP 404) within 60s; rate_flood: 30 requests to /geoserver/ (HTTP 404) within 10s. First seen: 2026-10-08. Risk score: 65/100.
show less
Web App Attack
Anonymous
2026-10-08 15:00:17
(1 hour ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
ππ·
bubausluge
2026-10-08 14:31:14
(1 hour ago)
Blocked by https://aegis.hr β Web Scanner - (MITRE T1595.001), 138 attempts, Period: 2026-10-08 14:0 ...
show more
Blocked by https://aegis.hr β Web Scanner - (MITRE T1595.001), 138 attempts, Period: 2026-10-08 14:08:06 to 2026-10-08 14:08:07
show less
Web App Attack
Bad Web Bot
πΊπΈ
Rip
2026-10-08 14:23:37
(1 hour ago)
Authentication attack attempt. CMS Brute Force - Access Forbidden
Brute-Force
Web App Attack
π¦πΊ
nzhost.co.nz
2026-10-08 14:22:21
(1 hour ago)
$f2bV_matches
Hacking
Brute-Force
πΏπ¦
2k11.co.za
2026-10-08 14:21:47
(1 hour ago)
2026-10-08 10:19:11,846 fail2ban.actions [710]: NOTICE [nginx-bad-request] Ban 185.8.106.139 ...
show more
2026-10-08 10:19:11,846 fail2ban.actions [710]: NOTICE [nginx-bad-request] Ban 185.8.106.139
2026-10-08 10:21:46,590 fail2ban.actions [710]: NOTICE [nginx-botsearch] Ban 185.8.106.139
...
show less
Brute-Force
Anonymous
2026-10-08 14:20:02
(1 hour ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-08 14:19:32
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 185.8.106.139 (ip-185-8-106-139.004.ptr.cherrys ...
show more
(mod_security) mod_security (id:210730) triggered by 185.8.106.139 (ip-185-8-106-139.004.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:19:29.126675 2026] [security2:error] [pid 17551:tid 17551] [client 185.8.106.139:30024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ceezees.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ceezees.com"] [uri "/mailto:zydecomike-at-ceezees.com"] [unique_id "asemcfVDtwS84nuYc5qXhAAAAAE"], referer: https://ceezees.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-10-08 14:10:29
(1 hour ago)
36.175 requests in 1 hour (1w6d23h)
Brute-Force
Bad Web Bot
π³π±
Alt255
2026-10-08 14:08:50
(1 hour ago)
[ti-07al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 185.8.106.139 - - [08/Oct/2026:16:08:42 +0200] "GET /img../.git/config HTTP/1.1" 404 5881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 14:03:25
(2 hours ago)
185.8.106.139 - - [08/Oct/2026:16:03:24 +0200] "GET /.git/config HTTP/1.1" 404 23125 "-" "Mozilla/5. ...
show more
185.8.106.139 - - [08/Oct/2026:16:03:24 +0200] "GET /.git/config HTTP/1.1" 404 23125 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
185.8.106.139 - - [08/Oct/2026:16:03:24 +0200] "GET /.git/config HTTP/1.1" 404 5980 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
185.8.106.139 - - [08/Oct/2026:16:03:24 +0200] "GET /static../.git/config HTTP/1.1" 404 5980 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
185.8.106.139 - - [08/Oct/2026:16:03:24 +0200] "GET /static../.git/config HTTP/1.1" 404 23125 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
185.8.106.139 - - [08/Oct/2026:16:03:24 +0200] "GET /.git/index HTTP/1.1" 404 5980 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chr
...
show less
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-08 14:00:13
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
[email protected]
2026-10-08 13:59:18
(2 hours ago)
CrowdSec ban: crowdsecurity/thinkphp-cve-2018-20062 (duration: 71h59m49s)
Port Scan
πΊπΈ
TPI-Abuse
2026-10-08 13:55:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.8.106.139 (ip-185-8-106-139.004.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 185.8.106.139 (ip-185-8-106-139.004.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:55:54.487979 2026] [security2:error] [pid 6963:tid 6963] [client 185.8.106.139:41786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houstoun.me"] [uri "/lib../.git/config"] [unique_id "aseg6qSJv3GYvwg1kIqhwAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-10-08 13:55:39
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking