๐ฌ๐ง
stom
2026-07-29 19:36:52
(1 minute ago)
2026-07-29T19:36:51.484676ls.fionamaguire-art.com sshd[13834]: Invalid user georginamcmaster from 72 ...
show more
2026-07-29T19:36:51.484676ls.fionamaguire-art.com sshd[13834]: Invalid user georginamcmaster from 72.61.74.127 port 54816
...
show less
Brute-Force
SSH
๐ง๐พ
lns.bz
2026-07-29 14:48:48
(4 hours ago)
SSH bruteforce [BY]
SSH
๐ฌ๐ง
OptimusGO
2026-07-29 14:39:48
(4 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-29 15:39:48 UTC
Log evidence:
07/29/2026-15:39:47.786738 [**] [1:1000090:1] POLICY Unauthorized Management Port Access [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 72.61.74.127:34328 -> 185.127.18.66:22
show less
Port Scan
Brute-Force
๐จ๐ฆ
zXero
2026-07-29 06:23:55
(13 hours ago)
Fail2Ban automatic report - jail: geoip-ssh
Brute-Force
SSH
DDoS Attack
๐ฉ๐ช
Phenix Info
2026-07-29 05:57:50
(13 hours ago)
SmallGuard.fr/SSH Login Failed
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:02:13
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-26.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
Bedios GmbH
2026-07-26 19:46:16
(2 days ago)
Login credentials theft attempt
Hacking
๐ฟ๐ฆ
conure
2026-07-26 17:08:26
(3 days ago)
csagent: score 15.4: secrets grab x2; 2 domain(s) in 1m45s
Web App Attack
๐ฉ๐ช
4server
2026-07-26 15:44:39
(3 days ago)
[SunJul2617:44:37.4160632026][security2:error][pid1807264:tid1807393][client72.61.74.127:0]ModSecuri ...
show more
[SunJul2617:44:37.4160632026][security2:error][pid1807264:tid1807393][client72.61.74.127:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"restaurantgandria.ch\"][uri\"/app/.env\"][unique_id\"amYrZV0a6goI42nvzU2wcQAAARI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-26 08:42:03
(3 days ago)
Try to access /api/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 04:04:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 00:04:13.665151 2026] [security2:error] [pid 2475763:tid 2475763] [client 72.61.74.127:54406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimhermelband.com"] [uri "/app/.env"] [unique_id "amWHPS9glb5c2p58kyt14wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 00:50:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 20:50:23.264603 2026] [security2:error] [pid 2422073:tid 2422073] [client 72.61.74.127:42154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ammatusk.com"] [uri "/api/.env"] [unique_id "amVZz61DuCkf4UcHjer1zAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 00:06:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 20:06:09.279658 2026] [security2:error] [pid 2943184:tid 2943184] [client 72.61.74.127:46754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "llaira.com"] [uri "/app/.env"] [unique_id "amVPcYpdM0ginQpOXhk0KgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 21:52:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 17:52:40.164328 2026] [security2:error] [pid 16196:tid 16196] [client 72.61.74.127:58510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarahsmith.ws"] [uri "/.env"] [unique_id "amUwKIeHKQSWKrqrpjoqaAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 21:09:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 72.61.74.127 (srv1676644.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 17:09:27.888686 2026] [security2:error] [pid 2934838:tid 2934838] [client 72.61.74.127:40212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "websites4sale.xyz"] [uri "/env/.env"] [unique_id "amUmB8L67fajbL3LvgKatAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack