๐ฎ๐ฉ
sockominfo
2026-06-17 08:01:08
(1 day ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 5.1/10 (MEDIUM). Confidence: ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 5.1/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-17 07:00:09
(1 day ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 6/10 (MEDIUM). Reported by T ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 6/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 06:06:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 134.209.178.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.209.178.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 02:06:51.049554 2026] [security2:error] [pid 9255:tid 9263] [client 134.209.178.158:50906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.86"] [uri "/.env.save"] [unique_id "ajI5e6VRLdsCZj5L5ZrWJgAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
chronos
2026-06-17 05:58:39
(1 day ago)
Web traffic. Possible probing or exploitation attempts. | Port: 80 | Proto: TCP | Location: United K ...
show more
Web traffic. Possible probing or exploitation attempts. | Port: 80 | Proto: TCP | Location: United Kingdom, Slough
show less
Web App Attack
Bad Web Bot
Hacking
๐น๐ท
Threat.live
2026-06-17 05:05:03
(1 day ago)
Suspicious Connection Attempts
Brute-Force
๐ณ๐ฑ
Savvii
2026-06-17 03:03:34
(1 day ago)
15 attempts against mh-modsecurity-ban on chard
Brute-Force
Web App Attack
๐ง๐ท
SOC PR
2026-06-17 02:36:39
(1 day ago)
IPS: Web Server Enforcement Violation.
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-17 02:15:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 134.209.178.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.209.178.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 22:15:35.351405 2026] [security2:error] [pid 21725:tid 21728] [client 134.209.178.158:46952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.124"] [uri "/.git/HEAD"] [unique_id "ajIDRzBtv23mCa30TWOlTwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-17 01:33:01
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
donarev419
2026-06-17 01:14:42
(1 day ago)
Port scan detected on port 2078 (connection without data transfer)
Port Scan
Anonymous
2026-06-17 01:14:02
(1 day ago)
[Tue Jun 16 18:13:56.693140 2026] [authz_core:error] [pid 1747457] [client 134.209.178.158:38968] AH ...
show more
[Tue Jun 16 18:13:56.693140 2026] [authz_core:error] [pid 1747457] [client 134.209.178.158:38968] AH01630: client denied by server configuration: /home/appowner/www/sec/.git
[Tue Jun 16 18:13:57.868947 2026] [authz_core:error] [pid 1747472] [client 134.209.178.158:38970] AH01630: client denied by server configuration: /home/appowner/www/sec/.git
[Tue Jun 16 18:13:59.033630 2026] [authz_core:error] [pid 1747469] [client 134.209.178.158:38978] AH01630: client denied by server configuration: /home/appowner/www/sec/.git
[Tue Jun 16 18:14:00.578372 2026] [authz_core:error] [pid 1747419] [client 134.209.178.158:58292] AH01630: client denied by server configuration: /home/appowner/www/sec/.git
[Tue Jun 16 18:14:01.941212 2026] [authz_core:error] [pid 1747399] [client 134.209.178.158:58300] AH01630: client denied by server configuration: /home/appowner/www/sec/.git
...
show less
Brute-Force
SSH
๐ซ๐ท
ingroscart.it
2026-06-17 01:13:00
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 134.209.178.158 (GB/United Kingdom/-)
SQL Injection
๐บ๐ธ
MPL
2026-06-17 01:02:12
(1 day ago)
tcp port scan (10 or more attempts)
Port Scan
๐ท๐ธ
Scan
2026-06-17 00:16:38
(1 day ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
๐ฎ๐ช
AutosOnShow
2026-06-17 00:15:06
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-06-17 00:14:27.807 |
Web App Attack