๐น๐ท
neron
2026-08-03 08:29:42
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-02 02:16:22
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-02 01:48:57
(2 weeks ago)
cloudlinux2 fail2ban: 2026-08-02 03:44:23,985 fail2ban.filter [1838]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-02 03:44:23,985 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.8.19.214 - 2026-08-02 03:44:23cloudlinux2 fail2ban: 2026-08-02 03:44:29,968 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 144.126.208.108 - 2026-08-02 03:44:28cloudlinux2 fail2ban: 2026-08-02 03:44:29,946 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.8.19.214 - 2026-08-02 03:44:29cloudlinux2 fail2ban: 2026-08-02 03:45:41,368 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 104.234.53.4 - 2026-08-02 03:45:40cloudlinux2 fail2ban: 2026-08-02 03:45:47,780 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.131.194.110 - 2026-08-02 03:45:46cloudlinux2 fail2ban: 2026-08-02 03:45:51,966 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.131.194.110 - 2026-08-02 03:45:51cloudlinux2 fail2ban: 2026-08-02 03:46:08,299 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.8.19.198 - 2026-08-02 03:46:07cloudlinux2
show less
Web App Attack
๐น๐ท
neron
2026-07-27 02:19:46
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-24 06:00:00
(4 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Vegascosmetics
2026-07-24 00:03:32
(4 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-23 12:19:47
(4 weeks ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 11:32:05
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 07:32:02.481651 2026] [security2:error] [pid 2719715:tid 2719715] [client 45.131.194.110:44107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bvisecurity.com"] [uri "/.env"] [unique_id "amH7suQEJGbvhUXEmS_zFAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-23 11:04:27
(4 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 08:42:05
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 04:42:01.136796 2026] [security2:error] [pid 2093642:tid 2093736] [client 45.131.194.110:33711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadingedgesupply.com"] [uri "/.env"] [unique_id "amHT2T4uGTHeXjSxd-l--gAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 06:02:15
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 02:02:08.884329 2026] [security2:error] [pid 224441:tid 224441] [client 45.131.194.110:63295] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eastbrooktech.com"] [uri "/.env"] [unique_id "amGuYCrlbFRnmOcthjxiMwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:33:57
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:33:51.853097 2026] [security2:error] [pid 2130948:tid 2130948] [client 45.131.194.110:34149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gegkal.com"] [uri "/.env"] [unique_id "amGnvyQxAcPaNLYOiC1u4AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 04:24:17
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:24:11.802010 2026] [security2:error] [pid 1722747:tid 1722747] [client 45.131.194.110:35201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achildsspace.com"] [uri "/.env"] [unique_id "amGXa8jrC7Le9bUjYlxmvAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 04:07:12
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:07:07.404053 2026] [security2:error] [pid 1744951:tid 1744951] [client 45.131.194.110:37587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edmontonatm.com"] [uri "/.env"] [unique_id "amGTa6xbcrBiDHNwqgtMbgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-07-23 03:34:51
(4 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack