🇫🇮
YF
2026-09-05 16:00:33
(25 minutes ago)
Htaccess probe
Web App Attack
🇮🇳
Starburst SysOp Team
2026-09-05 15:59:15
(26 minutes ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-bom2-2)
Hacking
Bad Web Bot
🇩🇪
s@ch@
2026-09-05 15:45:01
(41 minutes ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
🇩🇪
Enno
2026-09-05 15:34:47
(51 minutes ago)
P23::Fail2Ban: automated bot scanning / credential probing detected.
Web App Attack
Bad Web Bot
Anonymous
2026-09-05 15:21:08
(1 hour ago)
[Sat Sep 05 17:21:06.788513 2026] [:error] [pid 2605863:tid 2605863] [client 212.110.153.48:55920] M ...
show more
[Sat Sep 05 17:21:06.788513 2026] [:error] [pid 2605863:tid 2605863] [client 212.110.153.48:55920] ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `restricted-files.data' against variable `REQUEST_FILENAME' (Value: `/.ssh/id_dsa' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "131"] [id "930130"] [rev ""] [msg "Restricted File Access Attempt"] [data "Matched Data: .ssh/ found within REQUEST_FILENAME: /.ssh/id_dsa"] [severity "2"] [ver "OWASP_CRS/4.30.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [uri "/.ssh/id_dsa"] [unique_id "178862166687.790542"] [ref "o1,5v4,12t:utf8toUnicode,t:urlDecodeUni,t:normalizePathWin"]
[Sat Sep 05 17:21:06.790653 2026] [:error] [pid 2605834:tid 2605834] [client 212.110.153.48:55921]
...
show less
Web App Attack
🇫🇷
sthoyer.de
2026-09-05 15:06:25
(1 hour ago)
212.110.153.48 - - [05/Sep/2026:17:06:23 +0200] "GET /.env HTTP/1.1" 302 495 "-" "Mozilla/5.0 (Windo ...
show more
212.110.153.48 - - [05/Sep/2026:17:06:23 +0200] "GET /.env HTTP/1.1" 302 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:141.0) Gecko/20100101 Firefox/141.0"
212.110.153.48 - - [05/Sep/2026:17:06:23 +0200] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:141.0) Gecko/20100101 Firefox/141.0"
212.110.153.48 - - [05/Sep/2026:17:06:23 +0200] "GET /.ssh/id_dsa HTTP/1.1" 302 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:141.0) Gecko/20100101 Firefox/141.0"
...
show less
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-05 14:57:06
(1 hour ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-iad5-2)
Hacking
Bad Web Bot
Anonymous
2026-09-05 14:56:33
(1 hour ago)
nginx-444 from fail2ban
...
Web App Attack
Anonymous
2026-09-05 14:45:41
(1 hour ago)
Sep 5 16:45:40 mail2 Nextcloud[142593]: {"reqId":"apwrFHV47X9OVyvJDh8ktQAAAE4","level":1,"time":"20 ...
show more
Sep 5 16:45:40 mail2 Nextcloud[142593]: {"reqId":"apwrFHV47X9OVyvJDh8ktQAAAE4","level":1,"time":"2026-09-05T14:45:40+00:00","remoteAddr":"212.110.153.48","user":"--","app":"core","method":"GET","url":"/.ssh/id_dsa","scriptName":"/index.php","message":"Trusted domain error. \"212.110.153.48\" tried to access using \"178.254.3.7\" as host.","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:141.0) Gecko/20100101 Firefox/141.0","version":"32.0.9.2","data":{"app":"core"}}
Sep 5 16:45:40 mail2 Nextcloud[142580]: {"reqId":"apwrFCnwjflWVpOEbUoG_QAAAYc","level":1,"time":"2026-09-05T14:45:40+00:00","remoteAddr":"212.110.153.48","user":"--","app":"core","method":"GET","url":"/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"212.110.153.48\" tried to access using \"178.254.3.7\" as host.","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:141.0) Gecko/20100101 Firefox/141.0","version":"32.0.9.2","data":{"app":"core"}}
Sep 5 16:45:40 mail2 Nextcloud[126718
...
show less
Brute-Force
Web App Attack
🇺🇸
cwytech
2026-09-05 14:34:56
(1 hour ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/tpot-web-crit.
Bad Web Bot
Web App Attack
🇫🇮
mnazibo
2026-09-05 14:30:28
(1 hour ago)
Date: Sep 05 17:20:15 2026 EAT | Reported IP: 212.110.153.48 mod_security | id: 920350 930130 949110 ...
show more
Date: Sep 05 17:20:15 2026 EAT | Reported IP: 212.110.153.48 mod_security | id: 920350 930130 949110 | UA/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Host header is a numeric IP address; Host header is a numeric IP address; Host header is a numeric IP address; Host header is a numeric IP address; Host header is a numeric IP address; Host header is a numeric IP address; Host header is a numeric IP address; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 8); Inbound Anomaly Score Exceeded (Total Score: 8); Inbound Anomaly Score Exceeded (Total Score: 8); Host header is a numeric IP address; Host header is a numeric IP address; Restricted File Access Attempt; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 8); Inbound Anomaly Score Exceeded (Total Score: 8)
show less
SQL Injection
Brute-Force
Bad Web Bot
🇩🇪
LRob
2026-09-05 14:22:50
(2 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.ssh/id_dsa (+2 more) | 2026-09-05 14:22 UTC
show less
Hacking
Web App Attack
🇫🇷
bazter.pro
2026-09-05 14:06:36
(2 hours ago)
Auto-Ban [2026-09-05 17:06:35]: CRITICAL: .env attack [Paths: 9] | Details: Exploit trap paths: /.en ...
show more
Auto-Ban [2026-09-05 17:06:35]: CRITICAL: .env attack [Paths: 9] | Details: Exploit trap paths: /.env, /.git/config, /.ssh/id_dsa | Sensitive files/paths: /.env, /.git/config, /.ssh/id_dsa, /.htaccessLjaotPmesdlUJbtw, /.htaccessdrvzWFvv | 404 errors (9): /.env, /.ssh/id_dsa, /.htaccessdrvzWFvv, /TwyMSlcrQfMTBODT, /VkgwtOGX, /.htaccessLjaotPmesdlUJbtw, /.git/config, /adminDRqsWuusdYXMOAEC, /adminYjvvzJNo
show less
Web App Attack
Hacking
🇩🇪
paissangroup
2026-09-05 14:03:04
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
big-cloud.nl
2026-09-05 13:37:24
(2 hours ago)
Try to access /.git/config
Web App Attack