Anonymous
2025-10-06 00:21:40
(11 months ago)
Fail2Ban apache-noscript
Bad Web Bot
Anonymous
2025-10-05 23:53:42
(11 months ago)
92.223.85.212 - - [06/Oct/2025:01:52:18 +0200] "GET /wp-admin/user/admin.php HTTP/1.1" 404 497 "-" " ...
show more
92.223.85.212 - - [06/Oct/2025:01:52:18 +0200] "GET /wp-admin/user/admin.php HTTP/1.1" 404 497 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
92.223.85.212 - - [06/Oct/2025:01:52:18 +0200] "GET /warm.PhP7 HTTP/1.1" 404 496 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36"
92.223.85.212 - - [06/Oct/2025:01:52:18 +0200] "GET /wp-includes/sodium_compat/src/content.php HTTP/1.1" 404 496 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
92.223.85.212 - - [06/Oct/2025:01:52:18 +0200] "GET /wp-content/themes/hideo/network.php HTTP/1.1" 404 496 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/606.4.5 (KHTML, like Gecko) Version/11.1.2 Safari/606.4.5"
92.223.85.212 - - [06/Oct/2025:01:52:19 +0200] "GET /exit.PHP HTTP/1.1" 404 496 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, lik
...
show less
DDoS Attack
๐น๐ท
rtbh.com.tr
2025-09-06 20:08:39
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-09-05 20:08:37
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
Anonymous
2025-09-04 21:00:42
(1 year ago)
Infected user bad webscan
Exploited Host
๐ฉ๐ช
Bigbear3
2025-09-04 18:46:11
(1 year ago)
Report-by-bigbear3
Email Spam
Anonymous
2025-08-16 16:30:29
(1 year ago)
Failed login attempt detected by Fail2Ban in recidive jail
Brute-Force
๐ซ๐ท
ingroscart.it
2025-08-16 03:38:08
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted] 92.223.85.212 (SG/Singapore/vpn-gw-prod ...
show more
(mod_security) mod_security triggered on hostname [redacted] 92.223.85.212 (SG/Singapore/vpn-gw-prod-005.sin0-gcl.ff.avast.com)
show less
SQL Injection
๐ง๐ช
voormedia
2025-08-16 00:31:30
(1 year ago)
Accessed trap at '/.env'
Web App Attack
Anonymous
2025-08-15 22:38:40
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ซ๐ฎ
Mr-Money
2025-08-15 21:39:36
(1 year ago)
92.223.85.212 - - [15/Aug/2025:23:39:34 +0200] "GET /.env HTTP/1.1" 404 3732 "-" "Mozilla/5.0 (Windo ...
show more
92.223.85.212 - - [15/Aug/2025:23:39:34 +0200] "GET /.env HTTP/1.1" 404 3732 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
92.223.85.212 - - [15/Aug/2025:23:39:35 +0200] "GET /.env.bak HTTP/1.1" 404 3733 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
92.223.85.212 - - [15/Aug/2025:23:39:35 +0200] "GET /.env~ HTTP/1.1" 404 3733 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-15 15:30:21
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 92.223.85.212 (vpn-gw-prod-005.sin0-gcl.ff.avas ...
show more
(mod_security) mod_security (id:210492) triggered by 92.223.85.212 (vpn-gw-prod-005.sin0-gcl.ff.avast.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 15 11:30:12.207058 2025] [security2:error] [pid 24509:tid 24509] [client 92.223.85.212:21082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hodlmoser.com"] [uri "/.env"] [unique_id "aJ9ShEh9tKJOS8pjHCVBPAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-08-15 11:06:46
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 92.223.85.212 (SG/Singapore/vpn-gw-p ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 92.223.85.212 (SG/Singapore/vpn-gw-prod-005.sin0-gcl.ff.avast.com): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2025-08-15 10:35:43
(1 year ago)
Infected user bad webscan
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-08-15 07:53:25
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 92.223.85.212 (vpn-gw-prod-005.sin0-gcl.ff.avas ...
show more
(mod_security) mod_security (id:210492) triggered by 92.223.85.212 (vpn-gw-prod-005.sin0-gcl.ff.avast.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 15 03:53:18.994283 2025] [security2:error] [pid 12142:tid 12142] [client 92.223.85.212:21152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "footballxp.com"] [uri "/.env"] [unique_id "aJ7nblkaPrdkysbrMlnzugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack