🇩🇪
verlon
2026-09-10 02:40:17
(36 minutes ago)
2026/09/10 04:40:10 [error] 83034#83034: *146022 access forbidden by rule, client: 38.248.95.214, se ...
show more
2026/09/10 04:40:10 [error] 83034#83034: *146022 access forbidden by rule, client: 38.248.95.214, server: gcomfort.hu, request: "GET /db.sql HTTP/2.0", host: "gcomfort.hu"
2026/09/10 04:40:11 [error] 83034#83034: *146023 access forbidden by rule, client: 38.248.95.214, server: gcomfort.hu, request: "GET /dump.sql HTTP/2.0", host: "gcomfort.hu"
2026/09/10 04:40:14 [error] 83034#83034: *146016 access forbidden by rule, client: 38.248.95.214, server: gcomfort.hu, request: "GET /database.sql HTTP/2.0", host: "gcomfort.hu"
...
show less
Hacking
Web App Attack
Anonymous
2026-09-10 02:39:40
(36 minutes ago)
Scan for .env Files at 2026-09-10T02:39:40+00:00
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 00:21:44
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 38.248.95.214 (214-95-248-38.static.reverse.lst ...
show more
(mod_security) mod_security (id:210492) triggered by 38.248.95.214 (214-95-248-38.static.reverse.lstn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 20:21:40.606744 2026] [security2:error] [pid 3528:tid 3528] [client 38.248.95.214:50927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greighhouse.com"] [uri "/.env"] [unique_id "aqH4FDUFfrqDjBl0_6WiFQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 06:21:39
(1 day ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 06:01:15
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇿🇦
conure.sh
2026-09-03 01:52:55
(1 week ago)
csagent: score 19.1: debug leftover probe x1, php 404 x1, secrets grab x1; 2 domain(s) in 8s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 23:43:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 38.248.95.214 (214-95-248-38.static.reverse.lst ...
show more
(mod_security) mod_security (id:210492) triggered by 38.248.95.214 (214-95-248-38.static.reverse.lstn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 19:43:31.333106 2026] [security2:error] [pid 29133:tid 29133] [client 38.248.95.214:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.frogmouthatx.com"] [uri "/.env"] [unique_id "api0o2TNaJR0_iDtZbLrfAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Rip
2026-09-02 21:38:06
(1 week ago)
Restricted File Access Attempts
Port Scan
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-02 21:01:15
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇵🇱
Budyn
2026-09-02 20:15:37
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.budyn.top | URI: /phpinfo.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-02 20:02:43
(1 week ago)
csagent: score 15.9: 404 noise floor x2, secrets grab x1, debug leftover probe x1; 1 domain(s) in 11 ...
show more
csagent: score 15.9: 404 noise floor x2, secrets grab x1, debug leftover probe x1; 1 domain(s) in 11s
show less
Web App Attack
🇮🇹
VHosting
2026-09-02 19:50:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇸🇬
pusathosting.com
2026-08-14 21:20:07
(3 weeks ago)
imap1 failed login
Brute-Force
🇸🇬
pusathosting.com
2026-08-05 04:45:08
(1 month ago)
imap1 failed login
Brute-Force
🇮🇩
sockominfo
2026-07-26 23:00:53
(1 month ago)
Zimbra: Login failures from malicious IP: 38.248.95.214. Threat Score: 6.2/10 (MEDIUM). Confidence: ...
show more
Zimbra: Login failures from malicious IP: 38.248.95.214. Threat Score: 6.2/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack