π©πͺ
JLKnoch Software GmbH
2026-09-17 04:02:09
(2 minutes ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
π³π±
Alt255
2026-09-17 03:32:27
(32 minutes ago)
[ti-10al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-10al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 45.138.12.25 - - [17/Sep/2026:05:32:05 +0200] "GET /actions/debug/default/index HTTP/2.0" 404 32547 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.138.12.25 - - [17/Sep/2026:05:32:05 +0200] "GET /api/datasources HTTP/2.0" 404 32565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.138.12.25 - - [17/Sep/2026:05:32:05 +0200] "GET /api/frontend/settings HTTP/2.0" 404 32547 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.138.12.25 - - [17/Sep/2026:05:32:05 +0200] "GET /ansible.cfg HTTP/2.0" 404 32538 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.138.12.25 - - [17/Sep/2026:05:32:05 +0200] "GET /acti
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 03:26:43
(38 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
πΊπΈ
kosada.com
2026-09-17 03:24:16
(40 minutes ago)
Repeated requests for suspicious nonexistent URLs, for example: /app/config/pimcore/google-api-priva ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /app/config/pimcore/google-api-private-key.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36")
show less
Web App Attack
πΊπΈ
ambor
2026-09-17 03:21:49
(43 minutes ago)
Attack type: wordpress_attack_attempt | Target: /api/requestlogs | UA: Mozilla/5.0 (Windows NT 10.0; ...
show more
Attack type: wordpress_attack_attempt | Target: /api/requestlogs | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWeb | Country: NL
show less
Web App Attack
Brute-Force
π³π±
Alt255
2026-09-17 03:01:47
(1 hour ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 45.138.12.25 - - [17/Sep/2026:05:01:45 +0200] "GET /.bzr/branch/branch.conf HTTP/2.0" 301 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-17 03:01:22
(1 hour ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 03:00:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.25 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:00:36.735972 2026] [security2:error] [pid 396:tid 396] [client 45.138.12.25:52184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/app/etc/local.xml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waveitgroup.com"] [uri "/app/etc/local.xml.additional"] [unique_id "aqtX1GS0luY5HGO-pCQxcwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 02:54:55
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 45.138.12.25 (LT/Lithuania/-)
SQL Injection
πΊπ¦
URAN Publishing Service
2026-09-17 02:52:07
(1 hour ago)
[17/Sep/2026:05:52:06 +0300] -- 45.138.12.25 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /a ...
show more
[17/Sep/2026:05:52:06 +0300] -- 45.138.12.25 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /app/config/pimcore/google-api-private-key.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-17 02:51:41
(1 hour ago)
Excessive multi-domain requests
Brute-Force
πΈπͺ
vaia.cloud
2026-09-17 02:50:01
(1 hour ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-17 02:49:11
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 45.138.12.25 (LT/Lithuania/-)
SQL Injection
π³π±
debestelapp
2026-09-17 02:40:12
(1 hour ago)
Web App Attack
π©πͺ
LRob
2026-09-17 02:29:15
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.bashrc | 2026-09-17 02:29 UTC
show less
Hacking
Web App Attack