π¦πΊ
2000cn.com.au
2026-09-27 19:32:42
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
π³π±
Alt255
2026-09-26 14:40:17
(1 week ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 216.247.106.114 - - [26/Sep/2026:16:40:08 +0200] "GET /.env HTTP/1.1" 404 4462 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 14:23:56
(1 week ago)
attempts to hack passwords
Web App Attack
π©πͺ
Bedios GmbH
2026-09-26 14:15:48
(1 week ago)
Login credentials theft attempt
Hacking
Anonymous
2026-09-26 13:48:22
(1 week ago)
[ns67.kdns.gr] httpd-config-scan: sites=global; logs=/var/log/httpd/access_log,/var/log/nginx/access ...
show more
[ns67.kdns.gr] httpd-config-scan: sites=global; logs=/var/log/httpd/access_log,/var/log/nginx/access.log; samples=/.env
show less
Hacking
Web App Attack
πΈπ¬
anotherwatcher
2026-05-06 08:08:15
(5 months ago)
bad bot
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-06 07:56:43
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.247.106.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 216.247.106.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 03:56:35.881330 2026] [security2:error] [pid 22942:tid 22942] [client 216.247.106.114:18821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.206"] [uri "/.env"] [unique_id "afr0M9Yw7COiuNWEdFGKywAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
FEWA
2026-05-06 07:32:42
(5 months ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-06 07:22:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.247.106.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 216.247.106.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 03:22:39.835770 2026] [security2:error] [pid 5712:tid 5712] [client 216.247.106.114:54277] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.98"] [uri "/.env"] [unique_id "afrsPwigANVbQh-gqwwNcgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
SilverZippo
2026-05-06 07:08:53
(5 months ago)
Web App Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-06 07:05:46
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 216.247.106.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 216.247.106.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 03:05:41.026070 2026] [security2:error] [pid 20924:tid 20924] [client 216.247.106.114:52199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.52"] [uri "/.env"] [unique_id "afroRY2dapz3DD1N5FpPhgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
london2038.com
2026-05-06 07:05:18
(5 months ago)
Malformed or malicious web request
216.247.106.114 - - [06/May/2026:09:05:15 +0200] "POST / HTTP/1.1 ...
show more
Malformed or malicious web request
216.247.106.114 - - [06/May/2026:09:05:15 +0200] "POST / HTTP/1.1" 404 12813 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Hacking
Web App Attack
π§π·
SOC PR
2026-05-06 06:57:59
(5 months ago)
IPS: Sensitive Configuration File Disclosure.
Hacking
π©πͺ
marzzzello
2025-09-30 04:24:02
(1 year ago)
Ports: 54x 29882
Port Scan