Anonymous
2025-12-05 16:30:40
(6 months ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
π¨π¦
Julio Covolato
2025-12-05 15:50:02
(6 months ago)
Imap or Submission login brute-force attacks.
Brute-Force
πΊπΈ
myagent.site
2025-10-01 02:38:38
(8 months ago)
Banned for posting to wp-login.php without referer {"log":"eric","pwd":"Eric_Pagan","wp-submit":"Log ...
show more
Banned for posting to wp-login.php without referer {"log":"eric","pwd":"Eric_Pagan","wp-submit":"Log In","redirect_to":"https:\/\/ericpagan.com\/wp-admin","testcookie":"1"}
show less
Hacking
Anonymous
2025-07-27 00:30:17
(10 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
Anonymous
2025-07-11 05:10:15
(11 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
π¨π³
ThreatBook.io
2025-06-24 22:57:58
(11 months ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/37.19.197.208
2025-06- ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/37.19.197.208
2025-06-24 01:32:26 /.env
show less
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-23 21:10:36
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 37.19.197.208 (unn-37-19-197-208.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 37.19.197.208 (unn-37-19-197-208.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 23 17:10:30.022965 2025] [security2:error] [pid 690528:tid 690528] [client 37.19.197.208:55449] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spacebooger.com"] [uri "/.env"] [unique_id "aFnCxhaFzFM08LAzQWXbbQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2025-06-23 20:31:26
(11 months ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2025-06-23 20:30:42
(11 months ago)
2.218 requests with url.path *.env
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-06-23 20:22:01
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 37.19.197.208 (unn-37-19-197-208.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 37.19.197.208 (unn-37-19-197-208.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 23 16:21:54.386623 2025] [security2:error] [pid 2545526:tid 2545526] [client 37.19.197.208:61209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gvimmobilier.com"] [uri "/.env"] [unique_id "aFm3YsaEtmHUN70r06szVgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΉ
Markus Woegerbauer
2025-06-23 20:20:23
(11 months ago)
(mod_security) mod_security triggered on hostname [redacted] 37.19.197.208 (US/United States/unn-37- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 37.19.197.208 (US/United States/unn-37-19-197-208.datapacket.com)
show less
SQL Injection
Anonymous
2025-06-23 20:17:11
(11 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-23 19:04:37
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 37.19.197.208 (unn-37-19-197-208.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 37.19.197.208 (unn-37-19-197-208.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 23 15:04:33.546848 2025] [security2:error] [pid 126097:tid 126097] [client 37.19.197.208:56615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.skinnywheels.com"] [uri "/.env"] [unique_id "aFmlQScCKxJo6jaY1eacpQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-23 18:40:42
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 37.19.197.208 (unn-37-19-197-208.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 37.19.197.208 (unn-37-19-197-208.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 23 14:40:38.202366 2025] [security2:error] [pid 1283670:tid 1283670] [client 37.19.197.208:59705] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.laradioactivitat.com"] [uri "/.env"] [unique_id "aFmfph7KBoAnunhQ4QCPRwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
β¨
2025-06-23 17:46:01
(11 months ago)
Domain : torresdealbanchez.com
Rule : env
2025-06-23 17:45:28 152.53.103.155 GET /.env - 80 - 37.19. ...
show more
Domain : torresdealbanchez.com
Rule : env
2025-06-23 17:45:28 152.53.103.155 GET /.env - 80 - 37.19.197.208 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 - torresdealbanchez.com 404 3 50 1456 216 1546 - -
show less
Hacking
SQL Injection