๐ฌ๐ง
openstrike.co.uk
2025-11-23 06:14:00
(8 months ago)
2 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
Anonymous
2025-11-23 04:30:54
(8 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ธ๐ช
SkyDancer
2025-11-23 02:04:06
(8 months ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
๐ฉ๐ช
FeG Deutschland
2025-11-23 01:48:47
(8 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
myagent.site
2025-11-23 01:23:08
(8 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐ฆ๐บ
MAGIC
2025-11-23 01:00:53
(8 months ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-22 23:32:13
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 134.255.216.77 (mail.staychessedup.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 134.255.216.77 (mail.staychessedup.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 18:32:08.792122 2025] [security2:error] [pid 26526:tid 26526] [client 134.255.216.77:65087] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "churchtop.com"] [uri "/.env"] [unique_id "aSJH-CnfyKcrRTd-cFLIZQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-22 22:36:03
(8 months ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2025-11-22 21:08:35
(8 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
Bedios GmbH
2025-11-22 21:08:30
(8 months ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2025-11-22 20:53:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 134.255.216.77 (mail.staychessedup.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 134.255.216.77 (mail.staychessedup.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 15:53:16.620440 2025] [security2:error] [pid 8610:tid 8610] [client 134.255.216.77:55920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avmcyber.com"] [uri "/.env"] [unique_id "aSIivBL680-5nQa3iPPgGAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-11-22 20:42:04
(8 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-22 20:25:24
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 134.255.216.77 (mail.staychessedup.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 134.255.216.77 (mail.staychessedup.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 15:25:19.019610 2025] [security2:error] [pid 11138:tid 11138] [client 134.255.216.77:54536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1st-pick.com"] [uri "/.env"] [unique_id "aSIcL6k9Q6JV2chO7R768QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
anotherwatcher
2025-11-22 20:21:57
(8 months ago)
bad bot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-22 20:10:15
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 134.255.216.77 (mail.staychessedup.com): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 134.255.216.77 (mail.staychessedup.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 15:10:09.525102 2025] [security2:error] [pid 21293:tid 21293] [client 134.255.216.77:50231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmcnow.com"] [uri "/.env"] [unique_id "aSIYoYTVU6jCl0AqLnVAfgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack