π¬π§
PeravixGroup
2026-05-15 12:23:29
(1 month ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
π¬π§
PeravixGroup
2026-05-07 12:06:03
(1 month ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
π¦πΊ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
πΊπΈ
TPI-Abuse
2026-02-13 09:20:27
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 04:20:20.826055 2026] [security2:error] [pid 2721:tid 2721] [client 104.207.41.122:16597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lanistandifer.com"] [uri "/site/.git/config"] [unique_id "aY7s1MKtN7w0UhQSRHAF2QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 09:01:19
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 04:01:11.110995 2026] [security2:error] [pid 5570:tid 5570] [client 104.207.41.122:12549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lamporix.com"] [uri "/admin/.env"] [unique_id "aY7oVzNIYTYSwJ0-k8US9QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 05:25:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 00:25:14.207713 2026] [security2:error] [pid 2487:tid 2487] [client 104.207.41.122:30913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knoxbestos.com"] [uri "/backend/.env"] [unique_id "aY61ujHGHLI6yTTd3fTT1gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 04:09:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 23:09:04.597235 2026] [security2:error] [pid 23706:tid 23706] [client 104.207.41.122:48625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingmanrents.com"] [uri "/.env.local"] [unique_id "aY6j4KXInuxQHJoNCj1FFAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 02:57:29
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 21:57:25.073523 2026] [security2:error] [pid 4544:tid 4544] [client 104.207.41.122:16069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ketsuri.com"] [uri "/site/.git/config"] [unique_id "aY6TFfVmv5JMjSVJn3BKTwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
Anytech
2026-02-13 02:54:25
(4 months ago)
CrowdSec detected: crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
πΊπΈ
aks4226
2026-02-12 20:08:32
(4 months ago)
Bot search, attacking common web applications.
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-12 17:34:30
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 12:34:22.986536 2026] [security2:error] [pid 29077:tid 29077] [client 104.207.41.122:60513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigskyprints.com"] [uri "/.env"] [unique_id "aY4PHmfAJDydGvGqZQeSzgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
sailor
2026-02-12 16:33:00
(4 months ago)
GET .../app/.env
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 20:20:06
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 15:20:00.572261 2026] [security2:error] [pid 20841:tid 20841] [client 104.207.41.122:62829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ebookbargainlist.com"] [uri "/api/.env"] [unique_id "aYuS8MUgKJQAt-pRekJVngAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 18:28:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.41.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 13:28:06.811869 2026] [security2:error] [pid 32451:tid 32451] [client 104.207.41.122:52235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "consultantspeakerauthortrainer.org"] [uri "/dev/.git/config"] [unique_id "aYt4tjJ7zwe7gi4KojIQBgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Jean Valjean
2025-12-30 23:23:27
(5 months ago)
Fail2ban Caboom : xmlrpc.php Abuse
SQL Injection
Web App Attack