๐ณ๐ฑ
homeshowdomain.nl
2026-05-18 21:59:50
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-05-18
Web App Attack
SSH
Hacking
๐ฌ๐ง
PeravixGroup
2026-05-08 06:42:37
(4 weeks ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ณ๐ฑ
jjnxpct
2026-02-16 04:54:47
(3 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /frontend/.env (Rule ID: 930130) - Restricted File Access Attempt
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-02-16 00:05:40
(3 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
Anonymous
2026-02-15 13:05:17
(3 months ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 06:46:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:46:52.534892 2026] [security2:error] [pid 6921:tid 6921] [client 104.207.34.97:49687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "talentguard.net"] [uri "/.env.staging"] [unique_id "aZFr3Gz1z_gY-SD7SnhfoQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-02-15 06:13:15
(3 months ago)
11 attacks on password grabbing URLs, VC URLs, env grabbing URLs:
GET /.aws/credentials HTTP/1.1
GET ...
show more
11 attacks on password grabbing URLs, VC URLs, env grabbing URLs:
GET /.aws/credentials HTTP/1.1
GET /api/.git/config HTTP/1.1
GET /config/.env HTTP/1.1
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-15 05:58:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:58:49.434111 2026] [security2:error] [pid 1425:tid 1425] [client 104.207.34.97:61235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swwpccpa.com"] [uri "/app/.env"] [unique_id "aZFgmZwMAntGd7awCEl6hQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-15 04:48:28
(3 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env.local (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .env found within REQUEST_FILENAME: /.env.local]
show less
Hacking
Web App Attack
Anonymous
2026-02-15 04:31:19
(3 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-02-15 04:29:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:29:45.869754 2026] [security2:error] [pid 1321555:tid 1321555] [client 104.207.34.97:41011] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stuartpearson.net"] [uri "/api/.env"] [unique_id "aZFLuYUsdVdEvphEdaOsnAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:04:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:04:00.176147 2026] [security2:error] [pid 31973:tid 31973] [client 104.207.34.97:9983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "st-maarten-fishing.com"] [uri "/frontend/.env"] [unique_id "aZE3oGHvwjj96M6UjE-DgwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 02:37:01
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:36:53.851259 2026] [security2:error] [pid 29437:tid 29437] [client 104.207.34.97:49639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sponsorzilla.com"] [uri "/v2/.git/config"] [unique_id "aZExRdW3ARdT9NPL5IXIMQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:36:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.34.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:36:29.300951 2026] [security2:error] [pid 20149:tid 20149] [client 104.207.34.97:18675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "muzenique.com"] [uri "/dev/.git/config"] [unique_id "aZEjHeLvtuVvvJ3sRSANKwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack