๐ฉ๐ช
onlyops.app
2026-07-13 13:00:11
(1 month ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
Anonymous
2026-07-13 03:00:01
(1 month ago)
DirectAdmin Auto Report (sepidandishe.ir.error.log)
Brute-Force
SSH
๐ฆ๐ฟ
scientra
2026-07-13 02:42:31
(1 month ago)
Directory or admin enumeration โ https://www.lolitta.shop/.env.production [detected by Bitwall WAF]
Web App Attack
Anonymous
2026-07-13 00:09:43
(1 month ago)
89.167.52.117 - - [13/Jul/2026:02:09:29 +0200] "GET /.git/HEAD HTTP/1.1" 403 124 "-" "domain-exposur ...
show more
89.167.52.117 - - [13/Jul/2026:02:09:29 +0200] "GET /.git/HEAD HTTP/1.1" 403 124 "-" "domain-exposure-checker/1.2"
89.167.52.117 - - [13/Jul/2026:02:09:29 +0200] "GET /.git/config HTTP/1.1" 403 124 "-" "domain-exposure-checker/1.2"
89.167.52.117 - - [13/Jul/2026:02:09:30 +0200] "GET /.git/HEAD HTTP/1.1" 403 124 "-" "domain-exposure-checker/1.2"
89.167.52.117 - - [13/Jul/2026:02:09:30 +0200] "GET /.git/config HTTP/1.1" 403 124 "-" "domain-exposure-checker/1.2"
89.167.52.117 - - [13/Jul/2026:02:09:31 +0200] "GET /.git/HEAD HTTP/1.1" 403 124 "-" "domain-exposure-checker/1.2"
89.167.52.117 - - [13/Jul/2026:02:09:31 +0200] "GET /.git/config HTTP/1.1" 403 124 "-" "domain-exposure-checker/1.2"
89.167.52.117 - - [13/Jul/2026:02:09:36 +0200] "GET /v2/ HTTP/1.1" 404 436 "-" "domain-exposure-checker/1.2"
89.167.52.117 - - [13/Jul/2026:02:09:36 +0200] "GET /v2/ HTTP/1.1" 404 243 "-" "domain-exposure-checker/1.2"
89.167.52.117 - - [13/Jul/2026:02:09:36 +0200] "GET /v2/ HTTP/1.1" 404 436 "-" "domain
...
show less
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-12 16:14:46
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-07-12 04:18:31
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-11 21:59:51
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-10.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-07-11 16:58:04
(1 month ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, GET /.git/config HTTP/1.1, GET /.git/HEA ...
show more
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, GET /.git/config HTTP/1.1, GET /.git/HEAD HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.local HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
debestelapp
2026-07-11 05:25:05
(1 month ago)
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-07-11 03:42:12
(1 month ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 03:25:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 89.167.52.117 (static.117.52.167.89.clients.you ...
show more
(mod_security) mod_security (id:210492) triggered by 89.167.52.117 (static.117.52.167.89.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 23:24:57.793535 2026] [security2:error] [pid 18326:tid 18326] [client 89.167.52.117:53150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carltonelyse.com"] [uri "/.env"] [unique_id "alG3iRuMFO0Cuy_oqBpOagAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-07-11 01:52:54
(1 month ago)
Blocked by YFC Security on https://parcl9.com โ type: directory_scan_attempts
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-07-10 20:35:15
(1 month ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 20:26:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 89.167.52.117 (static.117.52.167.89.clients.you ...
show more
(mod_security) mod_security (id:210492) triggered by 89.167.52.117 (static.117.52.167.89.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 16:26:09.050126 2026] [security2:error] [pid 23688:tid 23688] [client 89.167.52.117:56188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smartradios.info"] [uri "/.git/HEAD"] [unique_id "alFVYWrqwekDd1G0krvKawAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-10 19:25:01
(1 month ago)
suspicious request in access.log
Web App Attack