๐บ๐ธ
TPI-Abuse
2026-07-29 12:50:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.81.118.23 (drm7epc4.nktele.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 95.81.118.23 (drm7epc4.nktele.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 08:50:30.506533 2026] [security2:error] [pid 417714:tid 417714] [client 95.81.118.23:34996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vetline.eu"] [uri "/.env"] [unique_id "amn3FmHWtbo12GWUFwe9sAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-29 12:28:58
(13 hours ago)
cloudlinux2 fail2ban: 2026-07-29 14:24:02,362 fail2ban.filter [1584]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-29 14:24:02,362 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 91.193.232.216 - 2026-07-29 14:24:02cloudlinux2 fail2ban: 2026-07-29 14:24:00,739 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 91.193.232.219 - 2026-07-29 14:24:00cloudlinux2 fail2ban: 2026-07-29 14:24:00,741 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 91.193.232.212 - 2026-07-29 14:24:00cloudlinux2 fail2ban: 2026-07-29 14:24:10,841 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 95.81.118.23 - 2026-07-29 14:24:10cloudlinux2 fail2ban: 2026-07-29 14:25:22,024 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 136.144.35.94 - 2026-07-29 14:25:21cloudlinux2 fail2ban: 2026-07-29 14:25:17,585 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 136.144.35.94 - 2026-07-29 14:25:17cloudlinux2 fail2ban: 2026-07-29 14:25:27,743 fail2ban.filter [1584]: INFO [plesk-apache] Found 142.147.140.211 - 2026-07-29 14:25:27cloudl
show less
Web App Attack
๐ฉ๐ช
todix
2026-07-29 12:28:44
(13 hours ago)
Web App Attack Exploid from 95.81.118.23
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 08:29:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.81.118.23 (drm7epc4.nktele.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 95.81.118.23 (drm7epc4.nktele.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 04:29:12.757425 2026] [security2:error] [pid 3530:tid 3590] [client 95.81.118.23:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.humanet.io"] [uri "/.env"] [unique_id "amm52MKXfPrs0n8Jx3dGkAAAAgM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 06:56:10
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.81.118.23 (drm7epc4.nktele.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 95.81.118.23 (drm7epc4.nktele.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 02:56:02.567092 2026] [security2:error] [pid 3296637:tid 3296637] [client 95.81.118.23:42900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gh057.io"] [uri "/.env"] [unique_id "ammkAk2LydAMtKz2Nen78wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-07-29 06:44:19
(19 hours ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 06:39:18
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 95.81.118.23 (drm7epc4.nktele.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 95.81.118.23 (drm7epc4.nktele.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 02:39:11.577176 2026] [security2:error] [pid 31744:tid 31744] [client 95.81.118.23:59860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evolute.io"] [uri "/.env"] [unique_id "ammgD0pKCfUl077Fm1fF5QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
victoryur
2026-07-21 00:06:37
(1 week ago)
Reported by Fail2Ban on 24.finkont.ru (sshd)
Brute-Force
๐ฌ๐ง
andypiper
2026-06-18 01:03:01
(1 month ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ท๐บ
victoryur
2026-06-18 00:11:05
(1 month ago)
Reported by Fail2Ban on 24.finkont.ru (sshd)
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-06-16 19:19:00
(1 month ago)
Try to access /.env
Web App Attack
๐ณ๐ฑ
Lentini
2026-06-16 18:51:39
(1 month ago)
visuitslagen.nl: malicious request:/.env
Web App Attack
Anonymous
2026-06-16 18:47:06
(1 month ago)
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /.env HTTP/1.1, GET /users/sign_in HTTP/ ...
show more
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /.env HTTP/1.1, GET /users/sign_in HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
Interceptor_HQ
2026-06-11 16:06:59
(1 month ago)
request_uri: / -- automatic report --
Brute-Force
Hacking
๐ฎ๐ณ
evicky2002
2026-05-20 04:30:47
(2 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH