๐ซ๐ฎ
paissangroup
2026-08-28 18:10:38
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ท๐ด
iulianh
2026-08-28 16:08:03
(5 hours ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-28 14:26:41
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 130.211.198.156 (156.198.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 130.211.198.156 (156.198.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:26:36.136916 2026] [security2:error] [pid 24453:tid 24453] [client 130.211.198.156:37114] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.marshall-islands-boat-registration.com.boatregistrationdelaware.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.marshall-islands-boat-registration.com.boatregistrationdelaware.com"] [uri "/storage/logs/laravel.log"] [unique_id "apGanO03QoQXqF4Nr7ZcqwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-28 14:06:45
(7 hours ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 130.211.198.156 (US/United States/156.198.211. ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 130.211.198.156 (US/United States/156.198.211.130.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/28 16:06:42 [error] 1242869#1242869: *744201 access forbidden by rule, client: 130.211.198.156, server: oremcorazzati.it.orem.it, request: "GET /wp-config.php~ HTTP/1.1", host: "oremcorazzati.it"
2026/08/28 16:06:42 [error] 1242875#1242875: *744208 access forbidden by rule, client: 130.211.198.156, server: oremcorazzati.it.orem.it, request: "GET /wp-config.php.bak HTTP/1.1", host: "oremcorazzati.it"
2026/08/28 16:06:42 [error] 1242862#1242862: *744204 access forbidden by rule, client: 130.211.198.156, server: oremcorazzati.it.orem.it, request: "GET /wp-config.php.swp HTTP/1.1", host: "oremcorazzati.it"
show less
Port Scan
๐ฉ๐ช
hidemail.app
2026-08-28 13:47:52
(7 hours ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐ท๐บ
DZBOT
2026-08-28 13:36:33
(7 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 13:20:16
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-28 12:58:55
(8 hours ago)
2026/08/28 13:58:39 [error] 380594#380594: *1130951 access forbidden by rule, client: 130.211.198.15 ...
show more
2026/08/28 13:58:39 [error] 380594#380594: *1130951 access forbidden by rule, client: 130.211.198.156, server: superiorinnercore.game-host.org, request: "GET /.env HTTP/1.1", host: "superiorinnercore.game-host.org"
130.211.198.156 - - [28/Aug/2026:13:58:39 +0100] "GET /.env HTTP/1.1" 403 2599 "-" "crusader-worker/1.0"
2026/08/28 13:58:52 [error] 380594#380594: *1130952 access forbidden by rule, client: 130.211.198.156, server: superiorinnercore.game-host.org, request: "GET //.env HTTP/1.1", host: "superiorinnercore.game-host.org"
show less
Brute-Force
Web App Attack
๐ง๐ท
Halux
2026-08-28 12:36:57
(8 hours ago)
130.211.198.156 Probing protected path or service
Web App Attack
๐บ๐ธ
Aurealize
2026-08-28 12:29:54
(8 hours ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.env.loc ...
show more
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.env.local.
show less
Web App Attack
Hacking
๐ท๐ด
clauss
2026-08-28 12:16:40
(9 hours ago)
130.211.198.156 - - [28/Aug/2026:15:16:39 +0300] "GET /actuator/env HTTP/2.0" 404 201 "-" "crusader- ...
show more
130.211.198.156 - - [28/Aug/2026:15:16:39 +0300] "GET /actuator/env HTTP/2.0" 404 201 "-" "crusader-worker/1.0"
130.211.198.156 - - [28/Aug/2026:15:16:39 +0300] "GET /actuator/configprops HTTP/2.0" 404 201 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-28 12:14:46
(9 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:36:02
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 130.211.198.156 (156.198.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.198.156 (156.198.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:35:58.126809 2026] [security2:error] [pid 743687:tid 744375] [client 130.211.198.156:47924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marinkovich.name"] [uri "/.env.prod"] [unique_id "apFynjGE-0FL01hIKxt-eAAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 11:30:47
(9 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+12 more) | 2026-08-28 11:30 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 10:57:58
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack