๐น๐ท
neron
2026-08-03 08:29:42
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-08-02 08:18:25
(3 weeks ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐น๐ท
neron
2026-08-02 02:16:22
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-02 00:53:56
(3 weeks ago)
cloudlinux2 fail2ban: 2026-08-02 02:48:50,703 fail2ban.filter [1838]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-02 02:48:50,703 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.8.19.195 - 2026-08-02 02:48:50cloudlinux2 fail2ban: 2026-08-02 02:48:50,901 fail2ban.filter [1838]: INFO [recidive] Found 45.8.19.195 - 2026-08-02 02:48:50cloudlinux2 fail2ban: 2026-08-02 02:48:50,893 fail2ban.actions [1838]: NOTICE [plesk-wordpress] Ban 45.8.19.195cloudlinux2 fail2ban: 2026-08-02 02:48:47,211 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.8.19.195 - 2026-08-02 02:48:46cloudlinux2 fail2ban: 2026-08-02 02:49:20,423 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.8.19.219 - 2026-08-02 02:49:20cloudlinux2 fail2ban: 2026-08-02 02:49:32,736 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.8.19.219 - 2026-08-02 02:49:32cloudlinux2 fail2ban: 2026-08-02 02:49:24,619 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.8.19.219 - 2026-08-02 02:49:24cloudlinux2 fail2ban: 2026-08-02 02:49:32,956 fail2ban
show less
Web App Attack
๐น๐ท
neron
2026-07-27 02:19:46
(4 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-07-24 00:22:22
(1 month ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-07-23 23:59:27
(1 month ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 12:47:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 08:47:40.472571 2026] [security2:error] [pid 2807361:tid 2807361] [client 45.131.194.198:54859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gemexpressions.com"] [uri "/.env"] [unique_id "amINbEAOXSq0OlPlHg5DowAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-07-23 11:33:27
(1 month ago)
Web App Attack Exploid from 45.131.194.198
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 08:51:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 04:51:27.816577 2026] [security2:error] [pid 2093642:tid 2093765] [client 45.131.194.198:57191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "triestemagica.org"] [uri "/.env"] [unique_id "amHWDz4uGTHeXjSxd-l_RQAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-23 07:04:45
(1 month ago)
[ThuJul2309:04:40.1848052026][security2:error][pid1364341:tid1364450][client45.131.194.198:0]ModSecu ...
show more
[ThuJul2309:04:40.1848052026][security2:error][pid1364341:tid1364450][client45.131.194.198:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"feldenkraisticino.ch\"][uri\"/xmlrpc.php\"][unique_id\"amG9CH2l7yg_lHfPPZIdRwAAAY0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 06:12:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 02:12:00.251980 2026] [security2:error] [pid 234058:tid 234058] [client 45.131.194.198:34577] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kittysalterations.com"] [uri "/.env"] [unique_id "amGwsB2RTYRzS11Ll3ir5wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:47:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:47:48.735792 2026] [security2:error] [pid 1807040:tid 1807040] [client 45.131.194.198:57941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rkevinschneider.com"] [uri "/.env"] [unique_id "amGrBB3JyUGfUfiAPrGqVQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:30:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:30:49.660809 2026] [security2:error] [pid 2127108:tid 2127108] [client 45.131.194.198:58597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creektech.com"] [uri "/.env"] [unique_id "amGnCdf166v1WaVB9UEpwQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 04:45:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:45:36.061932 2026] [security2:error] [pid 1622112:tid 1622112] [client 45.131.194.198:40031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "a-absoluteseptic.com"] [uri "/.env"] [unique_id "amGccLl9QecAmEycpJzdnAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack