๐ฉ๐ช
LRob
2026-07-23 22:48:04
(1 hour ago)
CrowdSec: crowdsecurity/http-probing | req: /.env | 11 distinct paths | UA: Mozilla/5.0 (Windows NT ...
show more
CrowdSec: crowdsecurity/http-probing | req: /.env | 11 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 22:27:59
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 91.92.47.112 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 91.92.47.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 18:27:53.652775 2026] [security2:error] [pid 2826887:tid 2826887] [client 91.92.47.112:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlascoombs.com"] [uri "/.git/config"] [unique_id "amKVaeLMW9SnRlDgcdJLkgAAAAw"], referer: http://atlascoombs.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 21:23:54
(3 hours ago)
91.92.47.112 - - [23/Jul/2026:23:23:08 +0200] "GET /db.php HTTP/1.1" 404 29221
91.92.47.112 - - [23/ ...
show more
91.92.47.112 - - [23/Jul/2026:23:23:08 +0200] "GET /db.php HTTP/1.1" 404 29221
91.92.47.112 - - [23/Jul/2026:23:23:08 +0200] "GET /settings.php HTTP/1.1" 404 29221
91.92.47.112 - - [23/Jul/2026:23:23:08 +0200] "GET /config.js HTTP/1.1" 404 29861
91.92.47.112 - - [23/Jul/2026:23:23:08 +0200] "GET /docker-compose.yml HTTP/1.1" 404 29861
91.92.47.112 - - [23/Jul/2026:23:23:08 +0200] "GET /database.php HTTP/1.1" 404 29221
91.92.47.112 - - [23/Jul/2026:23:23:08 +0200] "GET /application.yml HTTP/1.1" 404 29861
91.92.47.112 - - [23/Jul/2026:23:23:49 +0200] "GET /config/parameters.yml HTTP/1.1" 404 29861
91.92.47.112 - - [23/Jul/2026:23:23:49 +0200] "GET /config.json HTTP/1.1" 404 29861
91.92.47.112 - - [23/Jul/2026:23:23:49 +0200] "GET /configuration.php HTTP/1.1" 404 29221
91.92.47.112 - - [23/Jul/2026:23:23:49 +0200] "GET /pinfo.php HTTP/1.1" 404 27681
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
hchristo
2026-07-23 21:10:34
(3 hours ago)
[Thu Jul 23 23:10:29.833385 2026] [proxy_fcgi:error] [pid 1286:tid 1363] [client 91.92.47.112:59068] ...
show more
[Thu Jul 23 23:10:29.833385 2026] [proxy_fcgi:error] [pid 1286:tid 1363] [client 91.92.47.112:59068] AH01071: Got error 'Primary script unknown', referer: http://viyolacp.de/info.php
[Thu Jul 23 23:10:29.838645 2026] [proxy_fcgi:error] [pid 1286:tid 1348] [client 91.92.47.112:59046] AH01071: Got error 'Primary script unknown', referer: http://viyolacp.de/wp-config.php
[Thu Jul 23 23:10:29.843687 2026] [proxy_fcgi:error] [pid 1286:tid 1378] [client 91.92.47.112:59082] AH01071: Got error 'Primary script unknown', referer: http://viyolacp.de/config.php
[Thu Jul 23 23:10:29.844025 2026] [proxy_fcgi:error] [pid 1286:tid 1351] [client 91.92.47.112:59044] AH01071: Got error 'Primary script unknown', referer: http://viyolacp.de/phpinfo.php
[Thu Jul 23 23:10:34.427513 2026] [proxy_fcgi:error] [pid 1286:tid 1338] [client 91.92.47.112:59102] AH01071: Got error 'Primary script unknown\n', referer: http://demo.viyolacp.de/info.php
...
show less
Brute-Force
๐ฉ๐ช
pscriptos
2026-07-23 20:01:36
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ท๐ด
iulianh
2026-07-23 18:57:16
(5 hours ago)
*
Brute-Force
SSH
๐จ๐ฟ
ddw
2026-07-23 18:28:22
(6 hours ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-23 18:15:02
(6 hours ago)
ModSecurity rule 949110 triggered on server. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
Major Hostility
2026-07-23 17:15:42
(7 hours ago)
"GET /appsettings.json HTTP/1.1" 404
"GET /server.js HTTP/1.1" 404
"GET /config.php HTTP/1.1" 404
"G ...
show more
"GET /appsettings.json HTTP/1.1" 404
"GET /server.js HTTP/1.1" 404
"GET /config.php HTTP/1.1" 404
"GET /.git/config HTTP/1.1" 404
"GET /app.js HTTP/1.1" 404
"GET /info.php HTTP/1.1" 404
"GET /.env HTTP/1.1" 404
"GET /phpinfo.php HTTP/1.1" 404
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-23 17:15:02
(7 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-07-23 15:17:15
(9 hours ago)
by Attack Lagwatch(gw)
DDoS Attack
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 15:04:43
(9 hours ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-23 13:48:51
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฏ๐ต
bokumin.org
2026-07-23 13:32:56
(11 hours ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.env"] [id "949110"] [m ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.env"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
๐ช๐ธ
alferez
2026-07-23 13:23:25
(11 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack