๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 21:59:11
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
Web App Attack
SSH
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-17 12:11:26
(6 days ago)
csagent: score 17.4: wp-config backup grab x2, 404 noise floor x2; 1 domain(s) in 18m56s
Web App Attack
๐ฉ๐ช
maxpower
2026-09-17 09:45:47
(6 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 89.116.212.244 (US/United States/srv1320 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 89.116.212.244 (US/United States/srv1320882.hstgr.cloud): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 89.116.212.244 - - [17/Sep/2026:11:45:44 +0200] "GET /pathscan-99940a52b5b0-nope.env HTTP/1.1" 200 12056 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-" host=mail.villapardi.it
show less
Port Scan
๐ซ๐ท
dynamix
2026-09-17 09:35:56
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-17 06:00:33
(6 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 04:03:19
(6 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 89.116.212.244 - - [17/Sep/2026:06:02:58 +0200] "GET /.env.txt HTTP/1.1" 301 437 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 03:39:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 89.116.212.244 (srv1320882.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 89.116.212.244 (srv1320882.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:39:47.501299 2026] [security2:error] [pid 11225:tid 11225] [client 89.116.212.244:37376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solar.catking.net"] [uri "/.env.txt"] [unique_id "aqthAwx7as-2XGIVay47vgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-17 02:45:02
(6 days ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 22:53:29
(6 days ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 89. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 89.116.212.244 - - [17/Sep/2026:00:53:28 +0200] "GET /.git/config HTTP/1.1" 301 544 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 21:58:39
(6 days ago)
Fail2ban Nginx log integration.
Brute-Force
SSH
Port Scan
๐ซ๐ท
solution.it
2026-09-16 06:50:53
(1 week ago)
[Wed Sep 16 08:50:52.760078 2026] [php7:error] [pid 1778785:tid 1778785] [client 89.116.212.244:4180 ...
show more
[Wed Sep 16 08:50:52.760078 2026] [php7:error] [pid 1778785:tid 1778785] [client 89.116.212.244:41806] script '/var/www/html/www.craccaaltesoro.it/phpinfo.php' not found or unable to stat
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:27:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 89.116.212.244 (srv1320882.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 89.116.212.244 (srv1320882.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:27:54.711950 2026] [security2:error] [pid 32451:tid 32451] [client 89.116.212.244:40410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.robertprowse.net"] [uri "/.env.txt"] [unique_id "aqm4Wm3r6YpyvUdhFT6gGgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-15 21:09:26
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 20:22:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 89.116.212.244 (srv1320882.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 89.116.212.244 (srv1320882.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:22:47.211775 2026] [security2:error] [pid 13198:tid 13198] [client 89.116.212.244:52174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kinnen.org"] [uri "/.git/config"] [unique_id "aqmpF3ECRsKqbBCq7_OeRgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:53:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 89.116.212.244 (srv1320882.hstgr.cloud): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 89.116.212.244 (srv1320882.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:52:55.417860 2026] [security2:error] [pid 10144:tid 10197] [client 89.116.212.244:37434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.isa-energy.net"] [uri "/.git/config"] [unique_id "aqmF97LxS6jRdy0S2GkXjwAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack