π³π±
homeshowdomain.nl
2026-09-03 22:03:09
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
π¬π§
neo101
2026-08-13 04:55:15
(3 weeks ago)
Confirmed AWS Honeytoken Exploitation: Host actively executed stolen AWS Canary credentials (KEY-42: ...
show more
Confirmed AWS Honeytoken Exploitation: Host actively executed stolen AWS Canary credentials (KEY-42: AKIAUE4EELJI7IKUOXI5 | Action: ListFoundationModels) harvested from decoy honeypot. Verified credential theft and unauthorized cloud API access.
show less
Hacking
Web App Attack
π§πͺ
madeit
2026-08-06 08:08:03
(4 weeks ago)
Web App Attack
π¬π§
OptimusGO
2026-08-01 08:22:14
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-01 09:22:14 UTC
Log evidence:
08/01/2026-09:22:07.199714 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 104.23.253.49:13255 -> 185.127.18.66:8443
08/01/2026-09:22:10.266364 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 104.23.253.49:13255 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
π¬π§
CrystalMaker
2026-07-02 01:31:37
(2 months ago)
Vulnerability scan - GET /__web_secure_probe_1782955891464754944.lock HTTP/2.0
Hacking
Anonymous
2026-04-24 20:29:50
(4 months ago)
Aggressive web scan
Web App Attack
Anonymous
2026-04-15 04:26:35
(4 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
π¨π¦
yukon.ca
2026-04-09 01:13:23
(4 months ago)
Web Server Enforcement Violation: Sensitive Configuration File Disclosure
Port:80
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2026-04-03 15:30:59
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 11:30:48.749353 2026] [security2:error] [pid 3710:tid 3710] [client 104.23.253.49:11602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.chadfishman.com"] [uri "/.env.development.local"] [unique_id "ac_dKM-Mr5D4QMlMR7zEywAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 03:27:57
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 23:27:45.022424 2026] [security2:error] [pid 25214:tid 25214] [client 104.23.253.49:11493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whaletailbikini.com"] [uri "/www/.env"] [unique_id "ac8zsYemjYvqcaaMAiJKsgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-03-21 00:19:42
(5 months ago)
Scanning/Probing (21)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 06:32:08
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:31:58.926819 2026] [security2:error] [pid 19831:tid 19831] [client 104.23.253.49:12530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.allisonannestudios.com"] [uri "/docker/.env.local"] [unique_id "abzp3uQ5_xWTyZIErXk5tQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 06:02:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:02:17.869899 2026] [security2:error] [pid 22169:tid 22169] [client 104.23.253.49:12983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.coryschubert.com"] [uri "/var/www/html/.env"] [unique_id "abzi6UF44eHT0X5P8GdSCgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:23:45
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:23:40.545760 2026] [security2:error] [pid 16487:tid 16487] [client 104.23.253.49:10822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bnaiisraelkearny.com"] [uri "/.env.local"] [unique_id "abzZ3FZTthGUZ0RWJ6O1oAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:03:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:03:35.045294 2026] [security2:error] [pid 18428:tid 18428] [client 104.23.253.49:13114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.peterndudar.com"] [uri "/.env.dev.local"] [unique_id "abzVJ6QnmqoLq_jsIbH-8wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack