Anonymous
2026-08-26 12:30:38
(2 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
π©πͺ
ger-stg-sifi1
2026-08-26 11:10:50
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 10:42:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 194.59.30.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.59.30.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:42:02.399266 2026] [security2:error] [pid 12439:tid 12439] [client 194.59.30.90:57335] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pagescigars.com"] [uri "/.env"] [unique_id "ao7C-mFCpJQzD8JIj0IhTwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-08-26 10:04:41
(2 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-197)
show less
Bad Web Bot
πΊπΈ
paulo.apoloni
2026-08-26 08:42:50
(2 days ago)
194.59.30.90 - - [26/Aug/2026:05:42:48 -0300] "GET //.env HTTP/2.0" 444 0 "http://cownter.agr.br//.e ...
show more
194.59.30.90 - - [26/Aug/2026:05:42:48 -0300] "GET //.env HTTP/2.0" 444 0 "http://cownter.agr.br//.env" "Go-http-client/2.0"
194.59.30.90 - - [26/Aug/2026:05:42:49 -0300] "GET //.env HTTP/2.0" 444 0 "http://cownter.agr.br//.env" "Go-http-client/2.0"
194.59.30.90 - - [26/Aug/2026:05:42:49 -0300] "GET //.env HTTP/2.0" 444 0 "http://cownter.agr.br//.env" "Go-http-client/2.0"
194.59.30.90 - - [26/Aug/2026:05:42:49 -0300] "GET //.env HTTP/2.0" 444 0 "http://cownter.agr.br//.env" "Go-http-client/2.0"
194.59.30.90 - - [26/Aug/2026:05:42:49 -0300] "GET //.env HTTP/2.0" 444 0 "http://cownter.agr.br//.env" "Go-http-client/2.0"
...
show less
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-26 08:12:07
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: app.astropot.website | URI: //.env | UA: Go-http-client/2.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 03:58:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 194.59.30.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.59.30.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 23:58:14.907670 2026] [security2:error] [pid 3164278:tid 3164337] [client 194.59.30.90:51332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "x2craftedchaos.life"] [uri "/.env"] [unique_id "ao5kVtpHqN4G1ESk5s6oewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
arsonist
2026-08-26 02:44:03
(2 days ago)
This IP accessed the path //.env, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 02:24:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 194.59.30.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.59.30.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:24:31.966907 2026] [security2:error] [pid 3083:tid 3083] [client 194.59.30.90:61599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starfateofficial.com"] [uri "/.env"] [unique_id "ao5OX2kzjLKutFR1UW4VmwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-08-26 01:11:41
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 00:59:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 194.59.30.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.59.30.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:59:30.549930 2026] [security2:error] [pid 28170:tid 28170] [client 194.59.30.90:50675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "decypher.design"] [uri "/.env"] [unique_id "ao46clFGNz7DdwXwiORSRwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 00:44:05
(2 days ago)
194.59.30.90 - - [26/Aug/2026:02:44:04 +0200] "GET //.env HTTP/1.1" 301 169 "-" "Go-http-client/1.1"
Web App Attack
π³π±
homeshowdomain.nl
2026-08-25 22:01:29
(2 days ago)
Auto-ban: >3000 req/min op 2026-08-25
Web App Attack
SSH
Hacking
π³π΄
Bots.go.to.hell
2026-08-25 22:00:29
(2 days ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
πΊπΈ
[email protected]
2026-08-25 21:47:31
(2 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-08-25T21:47:31Z
Brute-Force