๐ซ๐ท
masterguru
2026-04-03 04:29:16
(4 months ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-193)
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-04-02 22:05:23
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-01.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
big-cloud.nl
2026-04-02 14:40:35
(4 months ago)
Try to access /.aws/credentials
Web App Attack
๐จ๐ญ
Origon
2026-04-02 14:02:25
(4 months ago)
http-sensitive-files - IP: 104.156.225.195 - time="2026-04-02T16:02:25+02:00" level=info msg="(555f ...
show more
http-sensitive-files - IP: 104.156.225.195 - time="2026-04-02T16:02:25+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 104.156.225.195 (US/20473) : 4h ban on Ip 104.156.225.195" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 11:05:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.156.225.195 (104.156.225.195.vultruserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.156.225.195 (104.156.225.195.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 07:05:30.399921 2026] [security2:error] [pid 4866:tid 4866] [client 104.156.225.195:37334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.asiancommoditiescorporation.com"] [uri "/.env.backup"] [unique_id "ac5NemkPsVQNRWVrZKkkRAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 10:25:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.156.225.195 (104.156.225.195.vultruserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.156.225.195 (104.156.225.195.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 06:25:09.614247 2026] [security2:error] [pid 974:tid 974] [client 104.156.225.195:36962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anatolyaleksin.com"] [uri "/wp-config.php~"] [unique_id "ac5EBQetTQaZhG4iEyzm-gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-04-02 06:18:21
(5 months ago)
2026/04/02 06:18:21 [error] 157223#157223: *93564 access forbidden by rule, client: 104.156.225.195, ...
show more
2026/04/02 06:18:21 [error] 157223#157223: *93564 access forbidden by rule, client: 104.156.225.195, server: job-search-api.bridginggaps.tech, request: "GET /.env HTTP/1.1", host: "job-search-api.bridginggaps.tech"
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-01 22:42:00
(5 months ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-01 22:37:13
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.156.225.195 (104.156.225.195.vultruserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.156.225.195 (104.156.225.195.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 18:37:07.240754 2026] [security2:error] [pid 24607:tid 24607] [client 104.156.225.195:57534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amyisms.com"] [uri "/wp-config.php.save"] [unique_id "ac2eE7_shRSP6n3FLoX-VgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-01 20:01:49
(5 months ago)
Attempt to access sensitive files
Hacking
Web App Attack
๐ต๐ฑ
Ma ma
2026-04-01 06:06:00
(5 months ago)
page scanning
Web App Attack
Anonymous
2026-03-31 09:40:04
(5 months ago)
| PHPMyAdmin scans (looking for setup.php).
Web App Attack
Hacking
SQL Injection