🇮🇹
VHosting
2026-08-10 19:10:03
(2 weeks ago)
Detected mail brute force attack from 4 different servers
Brute-Force
🇩🇪
www.fransveldman.world
2026-07-13 12:39:20
(1 month ago)
Fetched browser challenge page 10 times in <2h without solving. Likely bad bot.
Bad Web Bot
🇩🇪
Da_tschek
2026-06-02 18:55:17
(2 months ago)
Port scanning
Port Scan
Hacking
🇺🇸
sgwid
2026-06-02 13:31:00
(2 months ago)
52.153.130.114 - - [02/Jun/2026:04:13:35 +0000] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Mozilla/5.0 ( ...
show more
52.153.130.114 - - [02/Jun/2026:04:13:35 +0000] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
52.153.130.114 - - [02/Jun/2026:04:13:41 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0"
52.153.130.114 - - [02/Jun/2026:04:13:42 +0000] "GET /.env.local HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
52.153.130.114 - - [02/Jun/2026:04:13:45 +0000] "GET /.env.production HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
52.153.130.114 - - [02/Jun/2026:04:13:48 +0000] "GET /.env.backup HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Mobile Safari/537.36"
show less
Brute-Force
Web App Attack
🇩🇪
Nightreaver
2026-06-02 07:10:48
(2 months ago)
52.153.130.114 - - [02/Jun/2026:09:10:40 0200] "GET /.env.local HTTP/1.1" 404 456 "-" "Mozilla/5.0 ...
show more
52.153.130.114 - - [02/Jun/2026:09:10:40 0200] "GET /.env.local HTTP/1.1" 404 456 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
52.153.130.114 - - [02/Jun/2026:09:10:43 0200] "GET /.env.production HTTP/1.1" 404 456 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0"
52.153.130.114 - - [02/Jun/2026:09:10:45 0200] "GET /.env.backup HTTP/1.1" 404 456 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0"
52.153.130.114 - - [02/Jun/2026:09:10:46 0200] "GET /.env.save HTTP/1.1" 404 456 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
52.153.130.114 - - [02/Jun/2026:09:10:47 0200] "GET /wp-config.php HTTP/1.1" 404 456 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"[...]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 06:58:03
(2 months ago)
by Attack Lagwatch(gw)
DDoS Attack
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 06:51:33
(2 months ago)
Jun 2 02:51:32 localhost kernel: [108728409.882191] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
Jun 2 02:51:32 localhost kernel: [108728409.882191] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=52.153.130.114 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=46 ID=56907 DF PROTO=TCP SPT=42113 DPT=2087 WINDOW=64240 RES=0x00 SYN URGP=0
Jun 2 02:51:32 localhost kernel: [108728409.882211] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=52.153.130.114 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=46 ID=56907 DF PROTO=TCP SPT=42113 DPT=2087 SEQ=898733005 ACK=0 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405A00402080A3F842D18000000000103030A)
Jun 2 02:51:32 localhost kernel: [108728410.093659] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=52.153.130.114 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=46 ID=42668 DF PROTO=TCP SPT=42132 DPT=2083 WINDOW=64240 RES=0x00 SYN URGP=0
Jun 2 02:51:32 localhost kernel: [108728410.093678] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:
show less
Port Scan
🇩🇪
ghostwarriors
2026-06-02 06:50:03
(2 months ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇳🇱
SysAdmin Dylan
2026-06-02 05:42:37
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 52.153.130.114 (US/United States/-): 10 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 52.153.130.114 (US/United States/-): 10 in the last 3600 secs
show less
Brute-Force
🇹🇷
SeczarSecureOps
2026-06-02 04:25:49
(2 months ago)
Auto-blocked by Seczar SecureOps — Port Scan Detection (8 events in 10min) at 2026-06-02 04:25
Port Scan
🇺🇸
conrad10781
2026-06-02 03:07:10
(2 months ago)
nginx-direct-ip
Port Scan
🇺🇸
Starburst SysOp Team
2026-06-02 02:39:40
(2 months ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-1)
Hacking
Bad Web Bot
🇩🇪
AetherFox
2026-06-02 02:28:58
(2 months ago)
AetherFox VoidGuard detected: [Tue Jun 02 02:28:54.428168 2026] [authz_core:error] [pid 2824550:tid ...
show more
AetherFox VoidGuard detected: [Tue Jun 02 02:28:54.428168 2026] [authz_core:error] [pid 2824550:tid 2824561] [client 52.153.130.114:42264] AH01630: client denied by server configuration: proxy:http://[MASKED]/.git/config
[Tue Jun 02 02:28:54.428374 2026] [authz_core:error] [pid 2824550:tid 2824561] [client 52.153.130.114:42264] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Tue Jun 02 02:28:56.046377 2026] [authz_core:error] [pid 2824550:tid 2824574] [client 52.153.130.114:42241] AH01630: client denied by server configuration: proxy:http://[MASKED]/.env
[Tue Jun 02 02:28:56.046540 2026] [authz_core:error] [pid 2824550:tid 2824574] [client 52.153.130.114:42241] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Tue Jun 02 02:28:57.670108 2026] [authz_core:error] [pid 2824551:tid 2824573] [client 52.153.130.114:42251] AH01630: client denied by server configuration: proxy:http://[MASKED]/.env.
...
show less
Bad Web Bot
Web App Attack
🇷🇸
Scan
2026-06-02 02:14:16
(2 months ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
🇹🇷
Threat.live
2026-06-02 01:45:04
(2 months ago)
Suspicious Connection Attempts
Brute-Force