๐ต๐ฑ
Budyn
2026-09-22 13:54:39
(6 minutes ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_1 | Action: AWS API Call | Token: jjbm ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_1 | Action: AWS API Call | Token: jjbmqxvagp71pskep78twdp5w | Client Tool: (no user-agent specified)
show less
Hacking
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-17 10:02:33
(5 days ago)
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 04:37:43
(1 week ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_1 | Action: AWS API Call | Token: jjbm ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_1 | Action: AWS API Call | Token: jjbmqxvagp71pskep78twdp5w | Client Tool: (no user-agent specified)
show less
Hacking
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-09 13:49:16
(1 week ago)
Web App Attack
๐ง๐ช
madeit
2026-08-23 17:21:17
(4 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-06 05:37:29
(1 month ago)
Web App Attack
๐บ๐ธ
mnsf
2026-06-16 00:16:24
(3 months ago)
Abuse Detected (2)
Brute-Force
Web App Attack
Anonymous
2026-04-15 05:05:56
(5 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 16:44:41
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 12:44:30.910297 2026] [security2:error] [pid 32352:tid 32352] [client 104.23.187.95:13204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amarrasdeescobar.com.cerrovictoria.com"] [uri "/.env.bak"] [unique_id "acqobukWKOIXSQLWyFqDPQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 05:25:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 01:25:25.517757 2026] [security2:error] [pid 604:tid 604] [client 104.23.187.95:9953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xyncom.com"] [uri "/.env_config"] [unique_id "ab4rxd5I4KRdxJd24sfOkgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:09:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:08:56.762786 2026] [security2:error] [pid 21268:tid 21268] [client 104.23.187.95:11755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cursoastrologia.verdadesreales.com"] [uri "/.env.test"] [unique_id "ab39uNuZL0jpw1DT4l9zjgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:12:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:12:08.198571 2026] [security2:error] [pid 14452:tid 14452] [client 104.23.187.95:11274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.emailautomationworkflow.com"] [uri "/.env~"] [unique_id "ab0PaPg_7OWoVXnIKKXVxgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:48:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:47:54.400020 2026] [security2:error] [pid 28409:tid 28409] [client 104.23.187.95:13104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bywaterpress.com"] [uri "/.env.dev.local"] [unique_id "ab0Juoxr-nkw65h56BHoMAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:51:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:51:17.239990 2026] [security2:error] [pid 30694:tid 30694] [client 104.23.187.95:12776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.consorciolegal.com"] [uri "/.git/refs/heads/main"] [unique_id "abzuZZ2SBEVBXe67J0qMBwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:41:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:41:43.507843 2026] [security2:error] [pid 30840:tid 30840] [client 104.23.187.95:9483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vespaitaliancafe.matteozacchino.dev"] [uri "/config/.env"] [unique_id "abzQBzL8uG11ZbVT2acAZQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack