๐ง๐ช
taivas.nl
2026-09-02 07:32:12
(10 minutes ago)
Bad_requests
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-09-02 07:20:01
(22 minutes ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-02 07:15:49
(26 minutes ago)
Enumerating paths that do not exist (scanning) | method: GET (+1 more) | path: / (+3 more) | 2026-09 ...
show more
Enumerating paths that do not exist (scanning) | method: GET (+1 more) | path: / (+3 more) | 2026-09-02 07:15 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TAY
2026-09-02 06:59:20
(43 minutes ago)
193.2.85.238 - - [02/Sep/2026:14:59:11 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 86671 "-" "Mozil ...
show more
193.2.85.238 - - [02/Sep/2026:14:59:11 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 86671 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
193.2.85.238 - - [02/Sep/2026:14:59:13 +0800] "GET /wp-config.php~ HTTP/1.1" 404 86671 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
193.2.85.238 - - [02/Sep/2026:14:59:15 +0800] "GET /wp-config.php.save HTTP/1.1" 404 86671 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
193.2.85.238 - - [02/Sep/2026:14:59:16 +0800] "GET /wp-config.php.old HTTP/1.1" 404 86671 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
193.2.85.238 - - [02/Sep/2026:14:59:17 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 86671 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
...
show less
Brute-Force
๐ฌ๐ง
consul.to
2026-09-02 06:36:08
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:27:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 193.2.85.238 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.2.85.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:26:58.831565 2026] [security2:error] [pid 862:tid 862] [client 193.2.85.238:49666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.3beeze.bridgital.com"] [uri "/wp-config.php.bak"] [unique_id "apfBssb-EwfI7uvF_UxoHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 05:41:07
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 193.2.85.238 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.2.85.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:40:58.558662 2026] [security2:error] [pid 32740:tid 32740] [client 193.2.85.238:39870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "99newmexicans.banis-associates.com"] [uri "/.git/config"] [unique_id "ape26qUKCATrpZVSosW9agAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-09-02 05:35:30
(2 hours ago)
F2B - Malicious activity detected. URL Probing. -151302cd-
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Alvino
2026-09-02 05:08:14
(2 hours ago)
Blocked due to abuseScore: 100
Web Spam
Hacking
Web App Attack
๐บ๐ธ
etu brutus
2026-09-02 03:57:39
(3 hours ago)
193.2.85.238 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-02 02:04:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 193.2.85.238 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.2.85.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 22:04:10.407650 2026] [security2:error] [pid 6858:tid 6858] [client 193.2.85.238:52954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.ontrek.com"] [uri "/wp-config.php.bak"] [unique_id "apeEGli0a7LJMAuObEIdDwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 01:40:02
(6 hours ago)
suspicious request in access.log
Web App Attack
๐ฌ๐ง
andypiper
2026-09-02 01:01:29
(6 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-09-02 00:22:03
(7 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, POST /?rest_route=/batch/v1 HT ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, POST /?rest_route=/batch/v1 HTTP/1.1, GET /.env.txt HTTP/1.1, GET /wp-config.php.txt HTTP/1.1, GET /.env HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /wp-config.php.old HTTP/1.1, GET /.env.bak HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.git/config HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.swp HTTP/1.1
show less
Hacking
Web App Attack
๐ต๐ฑ
tomkolp
2026-09-02 00:14:24
(7 hours ago)
CrowdSec - Scenario: crowdsecurity/http-cve-probing. Duration: 4h.
Web App Attack
Hacking