๐ฆ๐บ
paulshipley.com.au
2026-06-04 05:04:13
(15 hours ago)
[Thu Jun 04 15:04:12.940734 2026] [security2:error] [pid 453631] [client 134.122.24.190:54666] [clie ...
show more
[Thu Jun 04 15:04:12.940734 2026] [security2:error] [pid 453631] [client 134.122.24.190:54666] [client 134.122.24.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.env"] [unique_id "aiEHTH61WiyMSZxiscQzQAAAAAQ"]
...
show less
Web App Attack
๐จ๐ญ
4server
2026-06-03 06:05:08
(1 day ago)
[WedJun0308:05:00.5444792026][security2:error][pid1608348:tid1608801][client134.122.24.190:0]ModSecu ...
show more
[WedJun0308:05:00.5444792026][security2:error][pid1608348:tid1608801][client134.122.24.190:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"fisioterapiafalzone.ch\"][uri\"/.env\"][unique_id\"ah_EDLCNLRaLsW1mfsMfbgAAAIY\"]
show less
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-03 03:32:13
(1 day ago)
[Wed Jun 03 13:32:12.825208 2026] [security2:error] [pid 315464] [client 134.122.24.190:49794] [clie ...
show more
[Wed Jun 03 13:32:12.825208 2026] [security2:error] [pid 315464] [client 134.122.24.190:49794] [client 134.122.24.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dlcarterauthor.com"] [uri "/.env"] [unique_id "ah-gPHA0--2buhuvIQbMcAAAAAQ"]
...
show less
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-06-03 02:27:51
(1 day ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /.env | Pays: US | UA: Mozilla/5.0 (Kubuntu; Linux i686) ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /.env | Pays: US | UA: Mozilla/5.0 (Kubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-06-03 01:05:12
(1 day ago)
Abuse Detected (4)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 20:05:58
(2 days ago)
Abuse Detected (2)
Brute-Force
Web App Attack
Anonymous
2026-06-02 19:40:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-05-30 04:09:22
(5 days ago)
[Sat May 30 14:09:21.003020 2026] [security2:error] [pid 763419] [client 134.122.24.190:57722] [clie ...
show more
[Sat May 30 14:09:21.003020 2026] [security2:error] [pid 763419] [client 134.122.24.190:57722] [client 134.122.24.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.env"] [unique_id "ahpi8Xm3TWl6W3bMFejRGgAAAAs"]
...
show less
Web App Attack
๐ท๐บ
DZBOT
2026-05-29 12:15:16
(6 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-05-29 09:38:40
(6 days ago)
[Fri May 29 19:38:40.011221 2026] [security2:error] [pid 650819] [client 134.122.24.190:60858] [clie ...
show more
[Fri May 29 19:38:40.011221 2026] [security2:error] [pid 650819] [client 134.122.24.190:60858] [client 134.122.24.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dlcarterauthor.com"] [uri "/.env"] [unique_id "ahleoE_rbO08qpo_HF19dQAAAAw"]
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-05-29 07:05:51
(6 days ago)
Abuse Detected (2)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 03:44:11
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 134.122.24.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 134.122.24.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 23:44:07.684916 2026] [security2:error] [pid 21869:tid 21869] [client 134.122.24.190:35210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blacktieokc.com"] [uri "/.env"] [unique_id "ahkLhzpEeqSci_ciCYGRcgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-29 02:16:38
(6 days ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-29 02:16:38
(6 days ago)
IM360 WAF: Laravel .env file access
Web App Attack
๐บ๐ธ
interbiznw.com
2026-05-29 01:53:31
(6 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack