π³π±
Alt255
2026-10-03 15:01:53
(1 day ago)
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 209.50.162.237 - - [03/Oct/2026:17:01:19 +0200] "GET /admins/lara/phpinfo.php HTTP/1.1" 404 12532 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
boombies
2026-09-29 13:18:00
(5 days ago)
dsierra
Brute-Force
πΈπͺ
OnTheEdge
2026-09-03 11:40:47
(1 month ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
π«π·
Sklurk
2026-07-29 02:37:54
(2 months ago)
Web App Attack
Web App Attack
π¬π§
Oakley
2026-04-15 18:22:02
(5 months ago)
(antiscrape_rule) Web application abuse detected 209.50.162.237 (US/United States/-): 5 in the last ...
show more
(antiscrape_rule) Web application abuse detected 209.50.162.237 (US/United States/-): 5 in the last 900 secs
show less
Hacking
π¦πΊ
oncord
2026-03-12 15:51:41
(6 months ago)
Form spam
Web Spam
πΊπΈ
TPI-Abuse
2026-02-19 04:55:29
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 23:55:20.811259 2026] [security2:error] [pid 23803:tid 23803] [client 209.50.162.237:20721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konstantiasofokleous.com"] [uri "/v2/.git/config"] [unique_id "aZaXuIYOzF4caASJnLBLoAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 03:20:20
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:20:17.041693 2026] [security2:error] [pid 570618:tid 570618] [client 209.50.162.237:52677] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keysenterprise.com"] [uri "/admin/.env"] [unique_id "aZaBcZifzf7kXSlQqiQY6AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Swiptly
2026-02-19 03:05:34
(7 months ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 01:48:15
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 20:48:08.002501 2026] [security2:error] [pid 9828:tid 9828] [client 209.50.162.237:51977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karieva.com"] [uri "/.env.save"] [unique_id "aZZr2Bu5O5-3lYtQ3Y1_CQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-18 18:40:12
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:40:07.061034 2026] [security2:error] [pid 17954:tid 17954] [client 209.50.162.237:41597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thinkerblox.com"] [uri "/.env.production"] [unique_id "aZYHh_uXr5ikF915VzX0ZgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-02-18 16:51:57
(7 months ago)
Blocking for trying to access an exploit file: /.env.staging
Hacking
π©πͺ
ger-stg-sifi1
2026-02-18 14:08:47
(7 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-18 13:42:39
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:42:33.587165 2026] [security2:error] [pid 20825:tid 20825] [client 209.50.162.237:29695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "woahmanatee.com"] [uri "/new/.git/config"] [unique_id "aZXByUwRGvUl3NdFIqz8TwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-18 12:35:44
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:35:40.089229 2026] [security2:error] [pid 16242:tid 16242] [client 209.50.162.237:39521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wedeliverstrippers.com"] [uri "/.env.production"] [unique_id "aZWyHLpuv9n31vAwqsidrgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack