๐บ๐ธ
ambor
2026-07-24 17:06:20
(42 minutes ago)
Honeypot access: PHP file scan attempt: /config.php. Path: /config.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:39:40
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:39:32.051615 2026] [security2:error] [pid 4779:tid 4779] [client 104.28.254.132:62899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baughman.org"] [uri "/.env"] [unique_id "amOVRPs5BgTUZdTOHAYplQAAAA0"], referer: https://www.google.com/search?q=baughman.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-24 16:12:03
(1 hour ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-24 15:58:29
(1 hour ago)
104.28.254.132 - - [24/Jul/2026:18:58:26 +0300] "HEAD /.env HTTP/1.1" 404 4630 "-" "Mozilla/5.0 (Win ...
show more
104.28.254.132 - - [24/Jul/2026:18:58:26 +0300] "HEAD /.env HTTP/1.1" 404 4630 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
104.28.254.132 - - [24/Jul/2026:18:58:27 +0300] "GET /.env.development.local HTTP/1.1" 404 4691 "https://www.google.com/search?q=ee.zp.edu.ua" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:35:50
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:35:44.395987 2026] [security2:error] [pid 22687:tid 22687] [client 104.28.254.132:10685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/.env"] [unique_id "amOGULCY8XfV3NSKKVcYQgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:19:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:19:35.502307 2026] [security2:error] [pid 24516:tid 24516] [client 104.28.254.132:55599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityimprinting.abilityengraving.com"] [uri "/wp-config.php.bak"] [unique_id "amOCh9GJi8h53zEPpd-ifgAAABI"], referer: https://www.google.com/search?q=abilityimprinting.abilityengraving.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:57:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:57:50.164480 2026] [security2:error] [pid 3755127:tid 3755127] [client 104.28.254.132:17545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "80corvette.com"] [uri "/.env.local"] [unique_id "amN9bh1O5QP7qcTSFVY0IAAAABI"], referer: https://www.google.com/search?q=80corvette.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
langenkamp-media
2026-07-24 11:36:33
(6 hours ago)
Fail2Ban: Banned from jail nginx-nohome on 3dausdu.de
Web App Attack
๐ซ๐ท
masterguru
2026-07-24 10:12:19
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-07-24 08:45:07
(9 hours ago)
104.28.254.132 - - [24/Jul/2026:05:44:50 -0300] "GET /api/ HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compa ...
show more
104.28.254.132 - - [24/Jul/2026:05:44:50 -0300] "GET /api/ HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
104.28.254.132 - - [24/Jul/2026:05:45:04 -0300] "HEAD /wp-config.php HTTP/1.1" 404 0 "https://topvitrine.com.br/wp-config.php" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
104.28.254.132 - - [24/Jul/2026:05:45:06 -0300] "HEAD /.env.dist HTTP/1.1" 403 0 "https://topvitrine.com.br/.env.dist" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
104.28.254.132 - - [24/Jul/2026:05:45:06 -0300] "HEAD /.env.old HTTP/1.1" 403 0 "https://topvitrine.com.br/.env.old" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
104.28.254.132 - - [24/Jul/2026:05:45:06 -0300] "HEAD /config.yaml HTTP/1.1" 404 0 "https://topvitrine.com.br/config.yaml" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) Appl
...
show less
Port Scan
๐ฌ๐ง
sc user
2026-07-24 08:35:12
(9 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-24 06:17:22
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:17:09.286081 2026] [security2:error] [pid 3491130:tid 3491130] [client 104.28.254.132:34945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "disnet-m.com"] [uri "/.env.test"] [unique_id "amMDZb8AIqZ_zna2jd7J5AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-07-24 05:15:30
(12 hours ago)
2 attacks on env grabbing URLs:
HEAD /.env.sample HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 02:17:34
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 22:17:29.699258 2026] [security2:error] [pid 3828049:tid 3828049] [client 104.28.254.132:55161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsdepot.com"] [uri "/.env.development.local"] [unique_id "amLLOY8iQ5ycKUcn9rbaPgAAAAI"], referer: https://www.google.com/search?q=alsdepot.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-23 22:12:00
(19 hours ago)
[FriJul2400:11:53.5200052026][security2:error][pid544745:tid544966][client104.28.254.132:0]ModSecuri ...
show more
[FriJul2400:11:53.5200052026][security2:error][pid544745:tid544966][client104.28.254.132:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.eutecne.ch.81-17-25-250.cpanel.site\"][uri\"/.env.local\"][unique_id\"amKRqTgR5UTGzJbARVxNSQAAAQk\"]\,referer:https://www.google.com/search\?q=www.eutecne.ch.81-17-25-250.cpanel.site
show less
Hacking
Web App Attack