๐ซ๐ท
COMAITE
2026-07-30 06:04:13
(1 day ago)
Suspicious URL access.
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 days ago)
Automated Apache web application probing in selected 24h window; attempts=41, unique_paths=1, error_ ...
show more
Automated Apache web application probing in selected 24h window; attempts=41, unique_paths=1, error_responses=35; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 days ago)
Apache probe; attempts=41; exact paths: /xmlrpc.php
Web App Attack
๐ฎ๐น
Progetto1
2026-07-28 01:30:04
(3 days ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 21:59:39
(3 days ago)
Auto-ban: >3000 req/min op 2026-07-27
Web App Attack
SSH
Hacking
๐บ๐ธ
nationaleventpros.com
2026-07-27 12:39:57
(4 days ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:29:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.163.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.163.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:29:44.899391 2026] [security2:error] [pid 1799389:tid 1799419] [client 104.28.163.91:24652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "josephablumphotography.com"] [uri "/.env"] [unique_id "amclCLtjI3Vu78ATbdCWjAAAAhg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:14:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.163.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.163.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:14:35.852459 2026] [security2:error] [pid 1082500:tid 1082500] [client 104.28.163.91:51337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bccoa.net"] [uri "/wp-config.php.bak"] [unique_id "amb3S74t6LBGiAgQXMszYgAAAAU"], referer: https://www.google.com/search?q=bccoa.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-27 01:48:44
(4 days ago)
Try to access /.aws/credentials
Web App Attack
๐จ๐ญ
TheCoon
2026-07-27 01:15:01
(4 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 00:09:12
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.163.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.163.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 20:09:05.479857 2026] [security2:error] [pid 3691927:tid 3691927] [client 104.28.163.91:49735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "helloworld.jmnr.net"] [uri "/.git/HEAD"] [unique_id "amahoRHuG0lstcKfTi1ajgAAACY"], referer: https://www.google.com/search?q=helloworld.jmnr.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-26 23:22:47
(4 days ago)
[MonJul2701:22:41.2286492026][security2:error][pid2092166:tid2092400][client104.28.163.91:0]ModSecur ...
show more
[MonJul2701:22:41.2286492026][security2:error][pid2092166:tid2092400][client104.28.163.91:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.ticino-host.ch.hosting-domini.ch\"][uri\"/.env.bak\"][unique_id\"amaWwXmUo7w-3_T-TP6hOwAAAMg\"]\,referer:https://www.google.com/search\?q=www.ticino-host.ch.hosting-domini.ch
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-26 18:20:33
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 09:24:42
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.163.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.163.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 05:24:33.788062 2026] [security2:error] [pid 2906744:tid 2906744] [client 104.28.163.91:31916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nsightsound.com.mykelmilur.com"] [uri "/wp-config.php.bak"] [unique_id "amXSUfXDtca1Fa0wZ-nupQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-07-25 20:11:07
(5 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack