๐ฉ๐ช
ger-stg-sifi1
2026-07-26 02:01:26
(33 minutes ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 01:27:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 91.92.42.35 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 91.92.42.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 21:27:19.964601 2026] [security2:error] [pid 20135:tid 20135] [client 91.92.42.35:47990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "meghanmack.com"] [uri "/.env"] [unique_id "amVidyK0mOmLH0GvtJVAEQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-07-25 23:40:28
(2 hours ago)
Web App Attack Exploid from 91.92.42.35
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-25 22:15:34
(4 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 91.92.42.35 - - [26/Jul/2026:01:15:33 +0300] "GET ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 91.92.42.35 - - [26/Jul/2026:01:15:33 +0300] "GET /.git/config HTTP/1.1" 403 6275 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0"
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-07-25 21:18:41
(5 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-07-25 20:29:41
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-07-25 17:41:22
(8 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.achilles-collectors-place.gr; logs=/var/log/httpd/domain ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.achilles-collectors-place.gr; logs=/var/log/httpd/domains/achilles-collectors-place.gr.log; samples=/.git/config | /.env
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 17:02:51
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 91.92.42.35 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:949110) triggered by 91.92.42.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 13:02:42.851472 2026] [security2:error] [pid 2164110:tid 2164110] [client 91.92.42.35:50880] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ahws.cescfoundation.org"] [uri "/.git/config"] [unique_id "amTsMprgR_coLPpp0UbdNQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 15:09:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 91.92.42.35 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 91.92.42.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 11:09:34.033417 2026] [security2:error] [pid 1041897:tid 1041897] [client 91.92.42.35:41530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chrestian.com.gasoilliquidsdaily.com"] [uri "/.env"] [unique_id "amTRroiQqtxJ1i8kZg0XQAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 12:22:24
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 91.92.42.35 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 91.92.42.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 08:22:19.112397 2026] [security2:error] [pid 257094:tid 257094] [client 91.92.42.35:55624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sf2g.com.mrcd.org"] [uri "/.git/config"] [unique_id "amSqe9QR8Ft-u1YlSxYvCwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-07-25 03:59:31
(22 hours ago)
dot file probe
Web App Attack
๐ฑ๐บ
conseilgouz
2026-07-25 03:17:59
(23 hours ago)
are-17 : Block hidden directories=>/.git/config(/)
Hacking