๐ฟ๐ฆ
conure
2026-07-25 09:15:10
(3 hours ago)
csagent: score 20.0: wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0s
Web App Attack
๐ฆ๐บ
Bay13
2026-07-25 09:06:27
(3 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐บ๐ธ
xxkodedxx
2026-07-24 17:24:33
(19 hours ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: CA / AS13335 Cloudflare, Inc.
Active: 17:23:49 UTC
Volume: 1 HTTP req
Probed: /.env
Status mix: 444ร1
Vhost fishing: cards.zvxlabs.com
UA: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:39:38
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:39:32.306637 2026] [security2:error] [pid 24040:tid 24040] [client 104.28.222.134:15131] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baughman.org"] [uri "/wp-config.php"] [unique_id "amOVRFvi0HyCYyvC4y46ggAAABk"], referer: https://www.google.com/search?q=baughman.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-24 16:29:53
(20 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-07-24 16:25:41
(20 hours ago)
[Fri Jul 24 18:25:41.378249 2026] [security2:error] [pid 2241860:tid 2241877] [client 104.28.222.134 ...
show more
[Fri Jul 24 18:25:41.378249 2026] [security2:error] [pid 2241860:tid 2241877] [client 104.28.222.134:11794] [client 104.28.222.134] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.oh.mg.sus.fr"] [uri "/.env.development.local"] [unique_id "amOSBZUBRcnq_jLdjCjUcQAAAM8"], referer: https://www.google.com/search?q=www.oh.mg.sus.fr
[Fri Jul 24 18:25:41.396041 2026] [security2:error] [pid 2241860:tid 2241862] [client 104.28.222.134:32704] [client 104.28.222.134] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "I
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
6kilowatti
2026-07-24 16:07:32
(20 hours ago)
[24/Jul/2026:16:07:18 +0000] - 404 404 - GET https rupikonnaliisa.6kw.fi "/.env" [Client 104.28.222. ...
show more
[24/Jul/2026:16:07:18 +0000] - 404 404 - GET https rupikonnaliisa.6kw.fi "/.env" [Client 104.28.222.134] [Length 4606] [Gzip 3.94] [Sent-to 10.144.0.13] "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15" "https://www.google.com/search?q=rupikonnaliisa.6kw.fi"
[24/Jul/2026:16:07:20 +0000] - - 301 - GET http rupikonnaliisa.6kw.fi "/.git/HEAD" [Client 104.28.222.134] [Length 166] [Gzip -] [Sent-to 10.144.0.13] "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36" "https://www.google.com/search?q=rupikonnaliisa.6kw.fi"
[24/Jul/2026:16:07:21 +0000] - 404 404 - GET https rupikonnaliisa.6kw.fi "/.env.production" [Client 104.28.222.134] [Length 4606] [Gzip 3.94] [Sent-to 10.144.0.13] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0" "http://rupikonnaliisa.6kw.fi/.env.production"
[24/Jul/2026:16:07:31 +0000] - 404 404 - GET htt
...
show less
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-24 15:58:46
(20 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:35:45
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:35:41.389121 2026] [security2:error] [pid 18149:tid 18149] [client 104.28.222.134:59944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/.git/HEAD"] [unique_id "amOGTRWHGLrPUON_6q1G2QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:19:44
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:19:35.653430 2026] [security2:error] [pid 22818:tid 22818] [client 104.28.222.134:15649] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityimprinting.abilityengraving.com"] [uri "/.env.local"] [unique_id "amOCh0DuKGK3UEsfCQRzvwAAABQ"], referer: https://www.google.com/search?q=abilityimprinting.abilityengraving.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:57:33
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.222.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.222.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:57:29.183850 2026] [security2:error] [pid 3755713:tid 3755713] [client 104.28.222.134:50903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "80corvette.com"] [uri "/.env.test"] [unique_id "amN9WXBQaUjTrBJ0MTJHWwAAAAU"], referer: https://www.google.com/search?q=80corvette.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-24 12:23:28
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 104.28.222.134 - - [24/Jul/2026:15:23:27 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 104.28.222.134 - - [24/Jul/2026:15:23:27 +0300] "HEAD /.env.dist HTTP/1.1" 403 5429 "https://www.google.com/search?q=avx.gr" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
show less
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-07-24 11:53:24
(1 day ago)
Excessive HTTP request rate
Web App Attack
๐ฉ๐ช
langenkamp-media
2026-07-24 11:36:30
(1 day ago)
Fail2Ban: Banned from jail nginx-nohome on 3dausdu.de
Web App Attack
๐ซ๐ท
masterguru
2026-07-24 10:12:19
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack