🇩🇪
ghostwarriors
2026-09-08 21:50:05
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-08 21:34:29
(2 days ago)
192.227.104.230 - - [08/Sep/2026:23:34:26 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-std ...
show more
192.227.104.230 - - [08/Sep/2026:23:34:26 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 672 "-" "python-requests/2.32.5"
192.227.104.230 - - [08/Sep/2026:23:34:24 +0200] "GET /.env HTTP/1.1" 301 580 "-" "python-requests/2.32.5"
192.227.104.230 - - [08/Sep/2026:23:34:25 +0200] "GET /.env HTTP/1.1" 404 4497 "-" "python-requests/2.32.5"
show less
Web App Attack
Brute-Force
🇨🇭
Origon
2026-09-08 19:47:59
(2 days ago)
CVE-2017-9841 - IP: 192.227.104.230 - time="2026-09-08T21:47:58+02:00" level=info msg="(555f66b4f6a ...
show more
CVE-2017-9841 - IP: 192.227.104.230 - time="2026-09-08T21:47:58+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/CVE-2017-9841 by ip 192.227.104.230 (US/13886) : 4h ban on Ip 192.227.104.230" module=db
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:36:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.clou ...
show more
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.cloudsouth.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:36:08.137018 2026] [security2:error] [pid 13104:tid 13104] [client 192.227.104.230:53350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "illinois-online.org"] [uri "/.env"] [unique_id "aqBjqEki9_u8LK4-f8638gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-08 18:11:52
(2 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 192.227.104.230 (US/United States/192.22 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 192.227.104.230 (US/United States/192.227.104.230.hosted.at.cloudsouth.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 192.227.104.230 - - [08/Sep/2026:20:11:50 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 403 146 "-" "python-requests/2.32.5" "192.227.104.230" host=ilgiardinodeiciliegi.villapardi.it
show less
Port Scan
🇩🇪
maxpower
2026-09-08 17:51:04
(2 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 192.227.104.230 (US/United States/192.22 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 192.227.104.230 (US/United States/192.227.104.230.hosted.at.cloudsouth.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 192.227.104.230 - - [08/Sep/2026:19:51:02 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/2.0" 403 146 "-" "python-requests/2.32.5" "192.227.104.230" host=ilfaro.focusabruzzo.eu
show less
Port Scan
🇩🇪
LRob
2026-09-08 17:45:12
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-09-08 17:45 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:39:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.clou ...
show more
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.cloudsouth.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:39:16.812824 2026] [security2:error] [pid 1338:tid 1341] [client 192.227.104.230:59195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ilenefletcher.com.richardleeweatherman.com"] [uri "/.env"] [unique_id "aqBIRH9dEOHe-hXfEiiEMQAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-08 16:35:13
(2 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:07:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.clou ...
show more
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.cloudsouth.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:07:53.864884 2026] [security2:error] [pid 1864:tid 1864] [client 192.227.104.230:50172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ilanknapp.com"] [uri "/.env"] [unique_id "aqAy2XAUjKi7WHVh9CftfQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
findlab
2026-09-08 13:30:01
(2 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇯🇵
VXG-NET
2026-09-08 12:47:56
(2 days ago)
port=80, indicator_type=info-leak
Hacking
🇺🇸
TPI-Abuse
2026-09-07 21:18:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.clou ...
show more
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.cloudsouth.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:18:52.201514 2026] [security2:error] [pid 31200:tid 31200] [client 192.227.104.230:51348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ilovecoffeegroup.com"] [uri "/.env"] [unique_id "ap8qPF-dFSL-fLYGPMdaWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:30:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.clou ...
show more
(mod_security) mod_security (id:210492) triggered by 192.227.104.230 (192.227.104.230.hosted.at.cloudsouth.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:30:40.600748 2026] [security2:error] [pid 12371:tid 12371] [client 192.227.104.230:51404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redlinechemical.com"] [uri "/.env"] [unique_id "ap70wMpQQvwQrkniXdTBQgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-09-07 16:30:57
(3 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack