๐ณ๐ฑ
homeshowdomain.nl
2026-09-18 22:01:30
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
raph
2026-09-18 08:22:53
(3 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 06:54:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 67.21.33.135 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 67.21.33.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 02:54:37.573003 2026] [security2:error] [pid 25518:tid 25518] [client 67.21.33.135:62342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fredlandia.benshermanguitar.com"] [uri "/.env.development"] [unique_id "aqzgLZtDPlxQRbzf-9nQ2gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-18 06:18:33
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-18 04:11:51
(3 days ago)
2026/09/18 05:11:49 [error] 325888#325888: *84872 access forbidden by rule, client: 67.21.33.135, se ...
show more
2026/09/18 05:11:49 [error] 325888#325888: *84872 access forbidden by rule, client: 67.21.33.135, server: lisbon-pre-1755-earthquake.org, request: "GET /.env HTTP/2.0", host: "lisbon-pre-1755-earthquake.org"
2026/09/18 05:11:49 [error] 325891#325891: *84864 access forbidden by rule, client: 67.21.33.135, server: lisbon-pre-1755-earthquake.org, request: "GET /backend/.env HTTP/2.0", host: "lisbon-pre-1755-earthquake.org"
67.21.33.135 - - [18/Sep/2026:05:11:49 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6 Safari/605.1.15"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 15:13:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 67.21.33.135 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 67.21.33.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 11:13:45.876273 2026] [security2:error] [pid 17125:tid 17125] [client 67.21.33.135:58915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "limosnapa.com"] [uri "/.env.production"] [unique_id "aqwDqZ6naucQoi9hHo6XTgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
H24
2026-09-17 09:05:56
(4 days ago)
/settings.php /configuration.php /wp-config.php /database.php /.env /backend/.env /config.php
Web App Attack
๐ธ๐ฎ
administrator
2026-09-16 22:03:22
(4 days ago)
2026-09-16 19:10:15,822 fail2ban.actions [1067]: NOTICE [apache-badbots] Ban 67.21.33.135
20 ...
show more
2026-09-16 19:10:15,822 fail2ban.actions [1067]: NOTICE [apache-badbots] Ban 67.21.33.135
2026-09-16 19:10:15,877 fail2ban.actions [1067]: NOTICE [error-bots] Ban 67.21.33.135
2026-09-16 19:10:15,822 fail2ban.actions [1067]: NOTICE [apache-badbots] Ban 67.21.33.135
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 17:09:14
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ฟ๐ฆ
maximonline.co.za
2026-09-16 15:40:42
(5 days ago)
Brute Force SMTP AUTH Attack
Brute-Force
๐จ๐ฟ
unhfree.net
2026-09-16 15:06:30
(5 days ago)
Brute-Force
Exploited Host
๐ณ๐ฑ
johntps
2026-09-16 14:14:10
(5 days ago)
Automated honeypot defense: host probed a decoy/trap endpoint (/configuration.php) on a monitored we ...
show more
Automated honeypot defense: host probed a decoy/trap endpoint (/configuration.php) on a monitored web server; confirmed malicious and blocked.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
mnogoweb
2026-09-16 12:50:33
(5 days ago)
(smtpauth) Failed SMTP AUTH login from 67.21.33.135 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(smtpauth) Failed SMTP AUTH login from 67.21.33.135 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-16 06:43:14 login authenticator failed for (6BcYy1) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
2026-09-16 06:43:15 login authenticator failed for (9Cguydkx) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
2026-09-16 06:43:17 login authenticator failed for (zCaFkmE6W) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
2026-09-16 06:50:30 login authenticator failed for (YI23YiW) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
2026-09-16 06:50:31 login authenticator failed for (8PyoAsEG1p) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
Anonymous
2026-09-16 12:31:17
(5 days ago)
๐ฅ Web application attack detected. Vulnerability scanning and exploitation attempts identified.
Web App Attack
๐บ๐ธ
mnogoweb
2026-09-16 12:21:22
(5 days ago)
(smtpauth) Failed SMTP AUTH login from 67.21.33.135 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(smtpauth) Failed SMTP AUTH login from 67.21.33.135 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-16 06:11:18 login authenticator failed for (NK0skOfm) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
2026-09-16 06:11:19 login authenticator failed for (wbUTxr) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
2026-09-16 06:11:20 login authenticator failed for (96QdcaQ7BJ) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
2026-09-16 06:21:19 login authenticator failed for (6kuBAR) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
2026-09-16 06:21:20 login authenticator failed for (dMc6NCIgE) [67.21.33.135]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan