๐ง๐ช
sid3windr
2026-06-23 07:24:22
(8 hours ago)
GET /config/config.yaml (Tarpitted for , wasted 120B)
Web App Attack
๐ซ๐ท
Duggy_Tuxy๐งฑ
2026-06-22 20:14:23
(19 hours ago)
[HP02-SRV02-FR] Blocked by SysWarden Firewall (Port Scan / Probing)
Port Scan
๐จ๐ฟ
lp
2026-06-21 15:19:53
(2 days ago)
Email account brute force: 1 attempts were recorded from 195.93.253.245
2026-06-21T16:37:39+02:00 wa ...
show more
Email account brute force: 1 attempts were recorded from 195.93.253.245
2026-06-21T16:37:39+02:00 warning: static.245.253.93.195.ip.webhost1.net[195.93.253.245]: SASL PLAIN authentication failed: authentication failure, [email protected]
show less
Brute-Force
๐ฉ๐ช
Paul Smith
2026-06-20 19:02:01
(2 days ago)
Email Auth Brute force attack 2/1 in last day
Brute-Force
๐ฒ๐ณ
Public CSIRT/CC of Mongolia
2026-06-19 16:03:25
(3 days ago)
Honeypot hit: Incoming HTTP traffic on port 81
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-19 12:03:54
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 195.93.253.245 (static.245.253.93.195.ip.webhos ...
show more
(mod_security) mod_security (id:210730) triggered by 195.93.253.245 (static.245.253.93.195.ip.webhost1.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 08:03:48.680644 2026] [security2:error] [pid 27940:tid 27940] [client 195.93.253.245:53418] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.garyandthegroove.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.garyandthegroove.com"] [uri "/telegram_private.db"] [unique_id "ajUwJPCbEg1ximF0dJTq7QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-19 05:33:17
(4 days ago)
Automated report (2026-06-19T01:33:17-04:00). Caught probing for env file.
Hacking
Web App Attack
Anonymous
2026-06-19 05:17:12
(4 days ago)
Automated report (2026-06-19T01:17:12-04:00). Caught probing for env file.
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-06-17 22:03:00
(5 days ago)
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-17 11:15:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 195.93.253.245 (static.245.253.93.195.ip.webhos ...
show more
(mod_security) mod_security (id:210492) triggered by 195.93.253.245 (static.245.253.93.195.ip.webhost1.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 07:15:01.123202 2026] [security2:error] [pid 10033:tid 10058] [client 195.93.253.245:56390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "richardleeweatherman.com"] [uri "/.env.swp"] [unique_id "ajKBtQ2ZQycsYff-qfAPagAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ณ
Public CSIRT/CC of Mongolia
2026-06-17 08:27:04
(6 days ago)
Honeypot hit: Incoming HTTP traffic on port 81
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-16 01:46:12
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 195.93.253.245 (static.245.253.93.195.ip.webhos ...
show more
(mod_security) mod_security (id:210730) triggered by 195.93.253.245 (static.245.253.93.195.ip.webhost1.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 21:46:05.063653 2026] [security2:error] [pid 4947:tid 4959] [client 195.93.253.245:50666] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||coloradomohs.aafm.us|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coloradomohs.aafm.us"] [uri "/telegram_private.db"] [unique_id "ajCq3bR3Qak3uv14wYxRKgAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 16:05:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 195.93.253.245 (static.245.253.93.195.ip.webhos ...
show more
(mod_security) mod_security (id:210492) triggered by 195.93.253.245 (static.245.253.93.195.ip.webhost1.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 12:05:48.382257 2026] [security2:error] [pid 9795:tid 9795] [client 195.93.253.245:32772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.construction.bonefrog.com"] [uri "/.env.bak.1"] [unique_id "ajAi3GkGkfW7IP75UizCEwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ณ
Public CSIRT/CC of Mongolia
2026-06-15 15:36:35
(1 week ago)
Honeypot hit: Incoming HTTP traffic on port 81
Web App Attack
Bad Web Bot
๐ฉ๐ช
ecs.ge
2026-06-15 01:32:49
(1 week ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking