Anonymous
2026-07-01 04:34:39
(3 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
juguemosalacarioca.com
2026-06-28 22:47:48
(3 weeks ago)
Multiple HTTP calls attempting to GET resources using common/malformed API calls or formats on port ...
show more
Multiple HTTP calls attempting to GET resources using common/malformed API calls or formats on port 8080
show less
Web App Attack
๐ซ๐ท
largo-it.net
2026-06-28 16:45:07
(3 weeks ago)
Jun 28 18:44:43 vps-9f3cdc33 haproxy[984146]: 85.121.55.219:56662 [28/Jun/2026:18:44:43.423] www_fro ...
show more
Jun 28 18:44:43 vps-9f3cdc33 haproxy[984146]: 85.121.55.219:56662 [28/Jun/2026:18:44:43.423] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/56/66 404 3252 - - ---- 45/11/0/0/0 0/0 "GET /backend/.env HTTP/1.1"
Jun 28 18:44:43 vps-9f3cdc33 haproxy[984146]: 85.121.55.219:56662 [28/Jun/2026:18:44:43.922] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/43/53 404 3252 - - ---- 58/23/0/0/0 0/0 "GET /env HTTP/1.1"
Jun 28 18:44:44 vps-9f3cdc33 haproxy[984146]: 85.121.55.219:56730 [28/Jun/2026:18:44:44.364] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/51/62 404 3252 - - ---- 57/22/0/0/0 0/0 "GET /api/.env HTTP/1.1"
Jun 28 18:44:45 vps-9f3cdc33 haproxy[984146]: 85.121.55.219:56720 [28/Jun/2026:18:44:45.266] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/47/58 404 3252 - - ---- 58/22/0/0/0 0/0 "GET /.aws/credentials HTTP/1.1"
Jun 28 18:44:45 vps-9f3cdc33 haproxy[984146]: 85.121.55.219:56788 [28/Jun/2026:18:44:45.523] www_frontend~ finance_cluster/financ
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-28 11:23:11
(3 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-06-28 11:20:18
(3 weeks ago)
2026-06-28 @ 13:20:17 (CET) ~ Blocked for trying to access: /.env.production
Web App Attack
๐ฉ๐ช
lespbaj
2026-06-28 10:17:41
(3 weeks ago)
{"time":"2026-06-28T10:17:39+00:00","ip":"85.121.55.219","method":"GET","uri":"/.env.local","ua":"Mo ...
show more
{"time":"2026-06-28T10:17:39+00:00","ip":"85.121.55.219","method":"GET","uri":"/.env.local","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 15.7; rv:149.0) Gecko/20100101 Firefox/149.0","referer":""}
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-28 07:45:26
(3 weeks ago)
Try to access /.git/HEAD
Web App Attack
๐ฌ๐ง
Apache
2026-06-28 06:05:51
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 85.121.55.219 (-): 5 in the last 300 secs (CF_E ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.55.219 (-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Hary74656
2026-06-28 05:44:25
(3 weeks ago)
[Sun Jun 28 07:44:21.770530 2026] [security2:error] [pid 137382:tid 137576] [client 85.121.55.219:56 ...
show more
[Sun Jun 28 07:44:21.770530 2026] [security2:error] [pid 137382:tid 137576] [client 85.121.55.219:56450] [client 85.121.55.219] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ogenhance.aschi.at"] [uri "/.git/HEAD"] [unique_id "akC0tQhqjTyOnOdJKG7uAwAAA9g"]
[Sun Jun 28 07:44:22.460761 2026] [security2:error] [pid 137382:tid 137579] [client 85.121.55.219:56450] [client 85.121.55.219] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.env" at REQUEST_FILENAME. [file "/u
...
show less
Web App Attack
๐ง๐ช
boxed-it
2026-06-28 01:39:26
(4 weeks ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-27 22:31:58
(4 weeks ago)
Brute-Force
Web App Attack
๐ฉ๐ช
piticu iuli
2026-06-27 20:01:51
(4 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 85.121.55.219 (-)
SQL Injection
๐บ๐ธ
SLSLLC
2026-06-27 19:40:13
(4 weeks ago)
85.121.55.219 - - [27/Jun/2026:19:40:12 +0000] "GET /backend/.env HTTP/2.0" 403 1885 "-" "Mozilla/5. ...
show more
85.121.55.219 - - [27/Jun/2026:19:40:12 +0000] "GET /backend/.env HTTP/2.0" 403 1885 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/146.0.3856.109"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-06-27 07:59:27
(4 weeks ago)
2026/06/27 07:59:23 [error] 106155#106155: *333758674 access forbidden by rule, client: 85.121.55.21 ...
show more
2026/06/27 07:59:23 [error] 106155#106155: *333758674 access forbidden by rule, client: 85.121.55.219, server: finami.mx, request: "GET /.git/HEAD HTTP/2.0", host: "finami.mx"
2026/06/27 07:59:24 [error] 106157#106157: *333760969 access forbidden by rule, client: 85.121.55.219, server: finami.mx, request: "GET /.env HTTP/2.0", host: "finami.mx"
2026/06/27 07:59:24 [error] 106155#106155: *333758678 access forbidden by rule, client: 85.121.55.219, server: finami.mx, request: "GET /.env.local HTTP/2.0", host: "finami.mx"
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-06-27 07:44:14
(4 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack