๐บ๐ธ
mnsf
2026-09-20 06:05:10
(9 hours ago)
Scanning/Probing (19)
Brute-Force
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-20 05:14:25
(10 hours ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 0s
Web App Attack
Anonymous
2026-09-20 05:10:02
(10 hours ago)
suspicious request in access.log
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-20 04:53:56
(10 hours ago)
cloudlinux2 fail2ban: 2026-09-20 06:49:18,845 fail2ban.filter [1597]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-20 06:49:18,845 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 185.194.178.74 - 2026-09-20 06:49:18cloudlinux2 fail2ban: 2026-09-20 06:49:13,515 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 106.205.179.23 - 2026-09-20 06:49:13cloudlinux2 fail2ban: 2026-09-20 06:49:14,198 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 185.194.178.82 - 2026-09-20 06:49:13cloudlinux2 fail2ban: 2026-09-20 06:49:14,296 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 185.194.178.74 - 2026-09-20 06:49:13cloudlinux2 fail2ban: 2026-09-20 06:49:23,917 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 186.79.77.247 - 2026-09-20 06:49:23cloudlinux2 fail2ban: 2026-09-20 06:50:51,197 fail2ban.actions [1597]: NOTICE [plesk-modsecurity] Unban 103.147.0.24cloudlinux2 fail2ban: 2026-09-20 06:51:34,459 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 185.223.152.15 - 2026-09-20 06:51:33cloudlinux2 fail2ban: 2
show less
Web App Attack
๐ซ๐ท
regishoussin
2026-09-20 04:53:47
(10 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-20 04:53 UTC.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 04:29:41
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.106.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.106.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 00:29:34.672761 2026] [security2:error] [pid 23551:tid 23551] [client 20.106.209.149:52447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tausiet.com"] [uri "/.env"] [unique_id "aq9hLrUw6fVNJWfr48c28QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 04:09:58
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 03:54:34
(11 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 20.106.209.149 - - [20/Sep/2026:05:54:15 +0200] "GET /.env HTTP/2.0" 404 123372 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 03:52:40
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.106.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.106.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 23:52:32.736795 2026] [security2:error] [pid 9771:tid 9771] [client 20.106.209.149:59430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.env"] [unique_id "aq9YgA35bVbOKvXr8GlFAQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-20 03:49:59
(11 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
kosada.com
2026-09-20 03:49:28
(11 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env (HTTP/1.1 port 443, user agent ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36")
show less
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-19 06:30:31
(1 day ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /phpinfo, /.env, /ind ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /phpinfo, /.env, /index.php. Blocked at the edge.
show less
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-09-18 08:54:38
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 08:03:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.106.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.106.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 04:03:37.485964 2026] [security2:error] [pid 5849:tid 5949] [client 20.106.209.149:49784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mooks.chat"] [uri "/.env"] [unique_id "aqzwWdfaYL0SXOkIuIs5xgAAAgY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
moppetto
2026-09-18 01:34:46
(2 days ago)
Node.js .env file credential scraping; GET /.env
Bad Web Bot
Hacking