Anonymous
2026-07-20 16:33:37
(2 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ณ๐ฑ
homeshowdomain.nl
2026-07-18 22:02:39
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-17.
show less
Web App Attack
SSH
Hacking
๐ฎ๐ณ
evicky2002
2026-07-18 06:00:00
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-07-17 22:01:51
(2 days ago)
Auto-ban: >3000 req/min op 2026-07-17
Web App Attack
SSH
Hacking
๐จ๐ญ
TheCoon
2026-07-17 18:00:02
(3 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฉ๐ช
LRob
2026-07-17 16:41:21
(3 days ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: Mozilla/5.0 (Wind ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love;
show less
Hacking
๐ธ๐ฌ
wulan17
2026-07-17 10:40:57
(3 days ago)
Fail2ban: Web bot/vulnerability scanning detected.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-17 10:34:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:34:49.230817 2026] [security2:error] [pid 31171:tid 31171] [client 89.185.84.190:34876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hesterpark.braunfamily.info"] [uri "/.env.development"] [unique_id "aloFSYOpZIeXm6Cq-fe6WgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
blik2108
2026-07-17 10:26:26
(3 days ago)
beta.sleepylizard.com:443 89.185.84.190 - - [17/Jul/2026:11:26:22 +0100] "GET /config/.env HTTP/1.1" ...
show more
beta.sleepylizard.com:443 89.185.84.190 - - [17/Jul/2026:11:26:22 +0100] "GET /config/.env HTTP/1.1" 200 819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
beta.sleepylizard.com:443 89.185.84.190 - - [17/Jul/2026:11:26:23 +0100] "GET /config.js HTTP/1.1" 200 819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
beta.sleepylizard.com:443 89.185.84.190 - - [17/Jul/2026:11:26:23 +0100] "GET /config.json HTTP/1.1" 200 819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
beta.sleepylizard.com:443 89.185.84.190 - - [17/Jul/2026:11:26:25 +0100] "GET /config.py HTTP/1.1" 200 819 "-" "Mozilla/5.0 (Windows NT 10.0;
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-17 09:09:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 05:09:16.009981 2026] [security2:error] [pid 535610:tid 535610] [client 89.185.84.190:37530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psychoatomicpower.com"] [uri "/.env"] [unique_id "alnxPJGvHlSZqdOK8SamwAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-07-17 09:00:31
(3 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 08:38:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:38:15.657993 2026] [security2:error] [pid 9282:tid 9282] [client 89.185.84.190:58076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airdriedrivingschool.com"] [uri "/.env.production"] [unique_id "alnp9wknPZIdTYojiOUEZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 07:39:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 03:39:34.751962 2026] [security2:error] [pid 606064:tid 606064] [client 89.185.84.190:33758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.davidsonmanagement.net"] [uri "/.env.test"] [unique_id "alncNm5UAa7IX4gAi-RjewAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
Olexiy Backend
2026-07-17 07:17:54
(3 days ago)
89.185.84.190
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 05:37:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 89.185.84.190 (40316.ip-ptr.tech): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 01:37:44.124788 2026] [security2:error] [pid 426579:tid 426579] [client 89.185.84.190:40466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arcontractingservices.com"] [uri "/.env.dev"] [unique_id "alm_qOviQpN-AFU_WhOYtwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack