๐ฉ๐ช
ecs.ge
2026-04-16 22:52:02
(2 months ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐ฑ๐ป
garmtech.com
2026-04-13 22:09:21
(2 months ago)
IM360 WAF: Suspicious PHP objects in reguest
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-13 21:12:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 92.242.164.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 92.242.164.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 17:12:36.366464 2026] [security2:error] [pid 2203655:tid 2203655] [client 92.242.164.91:51870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danged.com"] [uri "/.env"] [unique_id "ad1cRB3XNGM90vi3TgqaBgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-04-13 15:48:55
(2 months ago)
Sensitive File Probe
Web App Attack
๐ฎ๐ฉ
Burayot
2026-04-13 08:44:29
(2 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 92.242.164.91 (FI/Finland/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 92.242.164.91 (FI/Finland/-): 1 in the last 3600 secs
show less
Web App Attack
๐ซ๐ท
Baking333
2026-04-13 08:33:09
(2 months ago)
[redacted] 92.242.164.91 - - [13/Apr/2026:09:33:07 +0100] "GET /.env HTTP/1.1" 302 5292 0/55961 "-" ...
show more
[redacted] 92.242.164.91 - - [13/Apr/2026:09:33:07 +0100] "GET /.env HTTP/1.1" 302 5292 0/55961 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2733.77 Safari/537.36" [redacted] 92.242.164.91 - - [13/Apr/2026:09:33:08 +0100] "GET /[redacted] HTTP/1.1" 302 1564 0/59919 "https://[redacted]/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2733.77 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-12 21:59:07
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-11.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
Baking333
2026-04-12 13:28:02
(2 months ago)
[redacted] 92.242.164.91 - - [12/Apr/2026:14:28:00 +0100] "GET /.env HTTP/1.1" 302 1533 0/67735 "-" ...
show more
[redacted] 92.242.164.91 - - [12/Apr/2026:14:28:00 +0100] "GET /.env HTTP/1.1" 302 1533 0/67735 "-" "Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2667.26 Safari/537.36" [redacted] 92.242.164.91 - - [12/Apr/2026:14:28:01 +0100] "GET /[redacted] HTTP/1.1" 302 1533 0/76962 "https://[redacted]/" "Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2667.26 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-11 21:59:24
(2 months ago)
Auto-ban: >3000 req/min op 2026-04-11
Web App Attack
SSH
Hacking
๐ฉ๐ช
netclix.gr
2026-04-11 09:46:44
(2 months ago)
(aggressive_scan) Aggressive Web Exploit Scan 92.242.164.91 (FI/Finland/-): 2 in the last 4600 secs; ...
show more
(aggressive_scan) Aggressive Web Exploit Scan 92.242.164.91 (FI/Finland/-): 2 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 92.242.164.91 - - [11/Apr/2026:12:46:23 +0300] "GET /0562cc2532cd.php HTTP/1.1" 404 808 "https://iqtelecom.gr/ajax/reload_basket_fly.php" "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko"
92.242.164.91 - - [11/Apr/2026:12:46:32 +0300] "GET /0562cc2532cd.php HTTP/1.1" 404 808 "https://iqtelecom.gr/include/mainpage/comp_sections.php" "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko"
show less
Port Scan
๐ณ๐ฑ
Savvii
2026-04-11 07:23:26
(2 months ago)
34 attempts against mh-misbehave-ban on ec102967
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-10 18:05:18
(2 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-04-10 11:28:23
(2 months ago)
20 attempts against mh-misbehave-ban on plum
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-10 06:00:04
(2 months ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 22:01:53
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 92.242.164.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.242.164.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 18:01:45.209208 2026] [security2:error] [pid 1447120:tid 1447120] [client 92.242.164.91:47266] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||troop9weymouth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "troop9weymouth.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adghyaelBfJgXGg69n3XkAAAAAM"], referer: http://troop9weymouth.com/wp-content/plugins/woocommerce-payments/readme.txt
show less
Brute-Force
Bad Web Bot
Web App Attack