π΅π±
dzpk
2026-07-22 01:23:13
(19 minutes ago)
217.160.68.147 - - [22/Jul/2026:03:23:12 +0200] "GET /wp-config.php HTTP/1.1" 404 261 "-" "Mozilla/5 ...
show more
217.160.68.147 - - [22/Jul/2026:03:23:12 +0200] "GET /wp-config.php HTTP/1.1" 404 261 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-22 01:19:22
(23 minutes ago)
(mod_security) mod_security (id:210492) triggered by 217.160.68.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.160.68.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 21:19:14.768341 2026] [security2:error] [pid 95444:tid 95444] [client 217.160.68.147:52479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.244"] [uri "/.env.old"] [unique_id "amAakkVHH_Ok1tGJGUOT3wAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
SysAdmin Dylan
2026-07-22 01:09:22
(33 minutes ago)
(mod_security) mod_security (id:210492) triggered by 217.160.68.147 (DE/Germany/-): 10 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 217.160.68.147 (DE/Germany/-): 10 in the last 3600 secs
show less
Brute-Force
π¬π§
andypiper
2026-07-22 01:00:46
(42 minutes ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
π©πͺ
maxpower
2026-07-22 00:54:45
(48 minutes ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 217.160.68.147 (DE/Germany/-): 1 in the ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 217.160.68.147 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 217.160.68.147 - - [22/Jul/2026:02:54:42 +0200] "GET /.aws/credentials HTTP/1.1" 404 10406 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "-" host=145.239.233.179
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-07-22 00:54:10
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 217.160.68.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.160.68.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 20:54:06.375836 2026] [security2:error] [pid 648473:tid 648473] [client 217.160.68.147:52751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.146"] [uri "/.env"] [unique_id "amAUrtYxcPaUV_ig42Yr1wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-07-22 00:46:56
(55 minutes ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.aws/credentials | 5 distinct paths | UA: Mozil ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.aws/credentials | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
Hacking
π©πͺ
Ba-Yu
2026-07-22 00:40:37
(1 hour ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
π·πΈ
Smel
2026-07-22 00:22:07
(1 hour ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
π©πͺ
Lino Project
2026-07-22 00:21:14
(1 hour ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
πΊπΈ
Starburst SysOp Team
2026-07-22 00:16:09
(1 hour ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-1)
Hacking
Bad Web Bot
π΅π±
nfsec.pl
2026-07-22 00:14:50
(1 hour ago)
217.160.68.147 - - [22/Jul/2026:00:14:50 +0000] "GET /.env.bak HTTP/1.1" 403 406 "-" "Mozilla/5.0 (W ...
show more
217.160.68.147 - - [22/Jul/2026:00:14:50 +0000] "GET /.env.bak HTTP/1.1" 403 406 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
217.160.68.147 - - [22/Jul/2026:00:14:50 +0000] "GET /.env HTTP/1.1" 403 406 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
217.160.68.147 - - [22/Jul/2026:00:14:50 +0000] "GET /.aws/credentials HTTP/1.1" 404 403 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
217.160.68.147 - - [22/Jul/2026:00:14:50 +0000] "GET /.aws/config HTTP/1.1" 404 403 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
217.160.68.147 - - [22/Jul/2026:00:14:50 +0000] "GET /.env.production HTTP/1.1" 403 406 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari
...
show less
Web App Attack
Exploited Host
π©πͺ
paissangroup
2026-07-22 00:04:59
(1 hour ago)
Multiple WAF Violations
Web App Attack
π©πͺ
tentwentyfour
2026-07-22 00:04:01
(1 hour ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
π¬π§
cg-design.co.uk
2026-07-21 23:43:32
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 217.160.68.147 (DE/Germany/-)
SQL Injection