🇫🇷
dynamix
2026-09-10 10:17:05
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇫🇷
mail.avx.gr
2026-09-10 10:10:22
(1 hour ago)
(nginxBACKUPSCAN) nginx backup/database-file scanner detected from 38.86.91.99 (US/United States/Vir ...
show more
(nginxBACKUPSCAN) nginx backup/database-file scanner detected from 38.86.91.99 (US/United States/Virginia/Charlottesville/-)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-10 10:06:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 38.86.91.99 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 38.86.91.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 06:06:28.830888 2026] [security2:error] [pid 24593:tid 24593] [client 38.86.91.99:56299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gavinnine.com.evannine.com"] [uri "/.env"] [unique_id "aqKBJP2VYmwof6YOgBGrvAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇿
Prcek
2026-09-10 07:57:25
(3 hours ago)
PortScan:HOST=38.86.91.99,DPORTS=80,443
Port Scan
🇫🇷
masterguru
2026-09-10 07:40:07
(4 hours ago)
Restricted File Access Attempt. Matched phrase "phpinfo.php" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 07:02:02
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 38.86.91.99 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 38.86.91.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 03:01:57.988183 2026] [security2:error] [pid 26147:tid 26147] [client 38.86.91.99:52580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gruponovak.com"] [uri "/.env"] [unique_id "aqJV5fofOhtNHuCO-PbpOgAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 06:30:02
(5 hours ago)
suspicious request in access.log
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-10 06:05:16
(5 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇸🇪
vaia.cloud
2026-09-10 06:05:02
(5 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-10 04:43:58
(6 hours ago)
cloudlinux2 fail2ban: 2026-09-10 06:40:36,410 fail2ban.actions [1892]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-10 06:40:36,410 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 38.86.91.99cloudlinux2 fail2ban: 2026-09-10 06:40:36,210 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 38.86.91.99 - 2026-09-10 06:40:36cloudlinux2 fail2ban: 2026-09-10 06:40:32,756 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 38.86.91.99 - 2026-09-10 06:40:32cloudlinux2 fail2ban: 2026-09-10 06:40:34,498 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 38.86.91.99 - 2026-09-10 06:40:34cloudlinux2 fail2ban: 2026-09-10 06:40:36,416 fail2ban.filter [1892]: INFO [recidive] Found 38.86.91.99 - 2026-09-10 06:40:36cloudlinux2 fail2ban: 2026-09-10 06:41:47,062 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 60.51.47.228 - 2026-09-10 06:41:47cloudlinux2 fail2ban: 2026-09-10 06:43:26,638 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 34.75.86.160cloudlinux2 fail2ban: 2026-09-10 06:43:26,214 fail2ban.filter
show less
Brute-Force
🇿🇦
conure.sh
2026-09-10 01:40:46
(10 hours ago)
csagent: score 17.9: backup/dump grab x2, secrets grab x1; 1 domain(s) in 10s
Web App Attack
🇬🇧
gws-hostmaster
2026-09-10 01:28:29
(10 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 5): Restricted File Access Attempt;URL file extension is restr ...
show more
ModSecurity OWASP CRS (Anomaly Score: 5): Restricted File Access Attempt;URL file extension is restricted by policy;
show less
Web App Attack
🇩🇪
HoneyPotFRI
2026-09-09 16:45:45
(18 hours ago)
38.86.91.99 - - [09/Sep/2026:18:45:29 +0200] "GET /phpinfo.php HTTP/1.1" 404 187 "-" "Mozilla/5.0 (W ...
show more
38.86.91.99 - - [09/Sep/2026:18:45:29 +0200] "GET /phpinfo.php HTTP/1.1" 404 187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3
...
show less
Bad Web Bot
Web App Attack
🇩🇪
todix
2026-09-09 16:32:11
(19 hours ago)
Web App Attack Exploid from 38.86.91.99
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:29:49
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 38.86.91.99 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 38.86.91.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:29:45.800368 2026] [security2:error] [pid 801:tid 801] [client 38.86.91.99:59863] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fernfieldbrooks.com"] [uri "/.env"] [unique_id "aqGJeYI-HZVsQEIBS6P9FQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack