๐จ๐ญ
zynex
2026-09-21 05:53:43
(12 minutes ago)
CrowdSec crowdsecurity/http-technology-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:11:39
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 41.251.12.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 41.251.12.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:11:34.764713 2026] [security2:error] [pid 29727:tid 29783] [client 41.251.12.3:52265] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vtweaversguild.org"] [uri "/.env"] [unique_id "arC8ho_RyAe_x-7YxDsq5gAAAY8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 05:07:04
(59 minutes ago)
Automated web scanner. Requested suspicious paths: /phpinfo.php | /test.php | /info.php | /info.php ...
show more
Automated web scanner. Requested suspicious paths: /phpinfo.php | /test.php | /info.php | /info.php | /phpinfo.php. UTC: 2026-09-21 04:31:24.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:54:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 41.251.12.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 41.251.12.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:54:43.050813 2026] [security2:error] [pid 24323:tid 24399] [client 41.251.12.3:64349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uoexpanse.com"] [uri "/.env"] [unique_id "arC4kwKC5Yw3N_6gqcheLAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-21 04:45:59
(1 hour ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ป๐ณ
trung.fun
2026-09-21 04:43:25
(1 hour ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
mieg
2026-09-21 04:39:47
(1 hour ago)
Web vulnerability probing
Brute-Force
Web App Attack
Anonymous
2026-09-21 04:38:16
(1 hour ago)
[21/Sep/2026:07:38:13 +0300] 178996549323.982212 41.251.12.3 58179 148.251.76.218 80
[21/Sep/2026:07 ...
show more
[21/Sep/2026:07:38:13 +0300] 178996549323.982212 41.251.12.3 58179 148.251.76.218 80
[21/Sep/2026:07:38:16 +0300] 178996549663.165387 41.251.12.3 58423 148.251.76.218 443
show less
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-09-21 04:24:59
(1 hour ago)
41.251.12.3 - - [21/Sep/2026:06:23:01 +0200] "GET /test.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 (compa ...
show more
41.251.12.3 - - [21/Sep/2026:06:23:01 +0200] "GET /test.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 (compatible; Bingbot/2.0; +http://www.bing.com/bingbot.htm)" "MA" "Marrakesh" "31.63480" "-8.00250"
41.251.12.3 - - [21/Sep/2026:06:23:01 +0200] "GET /phpinfo.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 (iPad; CPU OS 17_5 like Mac OS X) AppleWebKit/605.1.15 Version/17.5 Mobile Safari/604.1" "MA" "Marrakesh" "31.63480" "-8.00250"
41.251.12.3 - - [21/Sep/2026:06:23:01 +0200] "GET /info.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 Version/17.5 Mobile Safari/604.1" "MA" "Marrakesh" "31.63480" "-8.00250"
41.251.12.3 - - [21/Sep/2026:06:23:01 +0200] "GET /test.php HTTP/2.0" 404 36 "http://thedreamer.nl/test.php" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 Version/17.5 Mobile Safari/604.1" "MA" "Marrakesh" "31.63480" "-8.00250"
...
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
kosada.com
2026-09-21 04:24:17
(1 hour ago)
Repeated requests for suspicious nonexistent URLs, for example: /test.php (HTTP/2.0 port 443, user a ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /test.php (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.5 Safari/605.1.15")
show less
Web App Attack
๐ซ๐ท
tecnoacquisti.com
2026-09-21 04:19:02
(1 hour ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-21 04:01:21
(2 hours ago)
CMS/framework probe: 41.251.12.3 - - [21/Sep/2026:06:01:20 +0200] "GET /info.php HTTP/1.1" 301 178 " ...
show more
CMS/framework probe: 41.251.12.3 - - [21/Sep/2026:06:01:20 +0200] "GET /info.php HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; rv:126.0) Gecko/20100101 Firefox/126.0" asn=36903 org="Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM" country=MA
...
show less
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-21 03:32:04
(2 hours ago)
Triggered Cloudflare WAF (firewallCustom) from MA.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from MA.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /.env | UA: Mozilla/5.0 (Linux; Android 13; Pixel 8) AppleWebKit/537.36 Chrome/125.0.0.0 Mobile Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
wbsouza
2026-09-21 03:27:50
(2 hours ago)
CrowdSec: infra/bad-path-probe โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ง๐พ
lns.bz
2026-09-21 03:15:42
(2 hours ago)
.env scanning [BY]
Web App Attack