๐ฉ๐ช
TheDjRider
2026-09-22 14:13:35
(1 hour ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-22T14:13:31.641734369Z. Context: http_status=404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:26:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:26:20.533248 2026] [security2:error] [pid 24337:tid 24337] [client 13.59.251.94:53009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.117"] [uri "/.env"] [unique_id "arKB_CHGQg-22ipK9r3QDQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-22 11:01:45
(4 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-stl2-17)
Hacking
Bad Web Bot
๐ฉ๐ช
Mr-Money
2026-09-22 05:03:24
(10 hours ago)
13.59.251.94 - - [22/Sep/2026:07:03:23 +0200] "GET /.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (X11; Li ...
show more
13.59.251.94 - - [22/Sep/2026:07:03:23 +0200] "GET /.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:43:20
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:43:16.063281 2026] [security2:error] [pid 10373:tid 10373] [client 13.59.251.94:60456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.16"] [uri "/.env"] [unique_id "arGk9F769_UMlx5mfgMNPAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Don Felip
2026-09-21 21:40:33
(18 hours ago)
Web Exploiter - Banned by Fail2Ban
Hacking
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-21 20:45:48
(19 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
iNetWorker
2026-09-21 19:55:20
(19 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-21 18:50:06
(21 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-09-21 18:28:05
(21 hours ago)
Fail2Ban triggered
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:24:44
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:24:40.080168 2026] [security2:error] [pid 19906:tid 19906] [client 13.59.251.94:49988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.197"] [uri "/.env"] [unique_id "arF2aPm85P-zCGdZ5GcUSQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:59:58
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:59:54.036521 2026] [security2:error] [pid 27598:tid 27598] [client 13.59.251.94:50663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.50"] [uri "/.env"] [unique_id "arFwmkmoFhPytX_qf8xnJwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-21 17:49:10
(22 hours ago)
13.59.251.94 - - [21/Sep/2026:18:49:06 +0100] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Li ...
show more
13.59.251.94 - - [21/Sep/2026:18:49:06 +0100] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
2026/09/21 18:49:07 [error] 325888#325888: *1083599 access forbidden by rule, client: 13.59.251.94, server: [redacted], request: "GET /.env HTTP/1.1", host: "[redacted]"
13.59.251.94 - - [21/Sep/2026:18:49:07 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ซ๐ท
Little Iguana
2026-09-21 17:30:33
(22 hours ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 16:29:46
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.59.251.94 (ec2-13-59-251-94.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:29:39.427573 2026] [security2:error] [pid 7862:tid 7862] [client 13.59.251.94:51922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.43"] [uri "/.env"] [unique_id "arFbc4wdhVL5KGU_5KHJdQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack