๐ซ๐ท
mail.avx.gr
2026-07-23 11:31:30
(2 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 34.228.213.187 - - [18/Jul/2026:14:22:58 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 34.228.213.187 - - [18/Jul/2026:14:22:58 +0300] "GET /.git/config HTTP/1.1" 404 808 "-" "Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-21 21:59:40
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-20.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
lespbaj
2026-07-21 10:25:20
(4 days ago)
{"time":"2026-07-21T10:25:18+00:00","ip":"34.228.213.187","method":"GET","uri":"/.env","ua":"Mozilla ...
show more
{"time":"2026-07-21T10:25:18+00:00","ip":"34.228.213.187","method":"GET","uri":"/.env","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.9 Mobile/15E148 Safari/604.1","referer":""}
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-21 06:00:00
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฆ๐บ
nzhost.co.nz
2026-07-21 05:13:59
(4 days ago)
$f2bV_matches
Hacking
Brute-Force
๐จ๐ฆ
polycoda
2026-07-21 03:39:47
(4 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based)
show less
Hacking
Web App Attack
๐ฉ๐ช
wpadm4
2026-07-21 02:16:49
(4 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
on-com
2026-07-21 01:50:43
(4 days ago)
URL scan
Brute-Force
Web App Attack
๐จ๐ด
adalbertoreyes.org
2026-07-20 22:44:36
(4 days ago)
CategoryPortScan
Port Scan
๐ฉ๐ช
todix
2026-07-20 18:54:03
(4 days ago)
Web App Attack Exploid from 34.228.213.187
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 16:03:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.228.213.187 (ec2-34-228-213-187.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.228.213.187 (ec2-34-228-213-187.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 12:03:47.674451 2026] [security2:error] [pid 413:tid 413] [client 34.228.213.187:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.atlascoombs.com"] [uri "/.git/config"] [unique_id "al5G415dKJ87tmHhkEOMYAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-07-20 14:02:29
(5 days ago)
34.228.213.187 - - [20/Jul/2026:16:02:28 +0200] "GET /.env HTTP/1.1" 301 5668 "-" "Mozilla/5.0 (ZZ; ...
show more
34.228.213.187 - - [20/Jul/2026:16:02:28 +0200] "GET /.env HTTP/1.1" 301 5668 "-" "Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36"
34.228.213.187 - - [20/Jul/2026:16:02:28 +0200] "GET /.git/config HTTP/1.1" 301 5682 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Safari/605.1.15"
34.228.213.187 - - [20/Jul/2026:16:02:28 +0200] "GET /.env HTTP/1.1" 403 5407 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5 Safari/605.1.15"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 11:21:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.228.213.187 (ec2-34-228-213-187.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.228.213.187 (ec2-34-228-213-187.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:21:08.220073 2026] [security2:error] [pid 13905:tid 13905] [client 34.228.213.187:53432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chatari.ai"] [uri "/.git/config"] [unique_id "al4EpH0X_5TaLymxbmy4RwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-07-20 11:05:48
(5 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Rip
2026-07-20 10:21:26
(5 days ago)
Restricted File Access Attempts
Port Scan
Web App Attack