Anonymous
2026-10-10 23:58:04
(8 hours ago)
Authentication failure
Brute-Force
๐ซ๐ฎ
notelseit
2026-10-10 23:45:33
(8 hours ago)
2026-10-11T01:45:28.877135+02:00 mail postfix/submission/smtpd[1836853]: NOQUEUE: reject: RCPT from ...
show more
2026-10-11T01:45:28.877135+02:00 mail postfix/submission/smtpd[1836853]: NOQUEUE: reject: RCPT from unknown[194.5.49.88]: 450 4.7.25 Client host rejected: cannot find your hostname, [194.5.49.88]; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<c9Bwzv>
2026-10-11T01:45:33.498287+02:00 mail postfix/submission/smtpd[1836853]: warning: unknown[194.5.49.88]: SASL LOGIN authentication failed: (reason unavailable), [email protected]
2026-10-11T01:45:33.734548+02:00 mail postfix/submission/smtpd[1836853]: disconnect from unknown[194.5.49.88] ehlo=2 starttls=1 auth=0/1 commands=3/4
...
show less
Brute-Force
Email Spam
๐จ๐ฟ
unhfree.net
2026-10-10 23:42:23
(8 hours ago)
Brute-Force
Exploited Host
๐จ๐ฟ
unhfree.net
2026-10-01 10:38:19
(1 week ago)
Brute-Force
Exploited Host
๐ธ๐ฌ
Starburst SysOp Team
2026-09-30 01:52:20
(1 week ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-sin2-2)
Hacking
Bad Web Bot
๐ธ๐ฌ
anotherwatcher
2026-09-30 01:35:53
(1 week ago)
bad bot
Bad Web Bot
Anonymous
2026-09-27 12:23:46
(1 week ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 09:18:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 05:18:43.015436 2026] [security2:error] [pid 19452:tid 19452] [client 194.5.49.88:63379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.197"] [uri "/.env"] [unique_id "arjfc_ucxmrkNE9-AWK51QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 09:00:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 05:00:44.073832 2026] [security2:error] [pid 24584:tid 24584] [client 194.5.49.88:29503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.153"] [uri "/.env"] [unique_id "arjbPHkJQsuEjY4Eddqe9AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
cnaize
2026-09-27 08:48:40
(1 week ago)
Malicious activity blocked by Meds firewall
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-27 08:40:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 04:40:10.594151 2026] [security2:error] [pid 22157:tid 22157] [client 194.5.49.88:50527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.159"] [uri "/.env"] [unique_id "arjWarfV_E_d7q0ZUO9D-QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-27 08:34:18
(1 week ago)
automatically banned
Brute-Force
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-27 08:28:11
(1 week ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 08:08:40
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 04:08:34.986022 2026] [security2:error] [pid 2408:tid 2425] [client 194.5.49.88:35141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.79"] [uri "/.env"] [unique_id "arjPApwEamLslpuwMLsJ3gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 07:32:03
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.49.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 03:31:55.657451 2026] [security2:error] [pid 3624:tid 3630] [client 194.5.49.88:32217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.22"] [uri "/.env"] [unique_id "arjGa2sANP66DrG-e658KQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack