๐ณ๐ฑ
homeshowdomain.nl
2026-10-09 21:59:58
(6 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-08.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:14:44
(23 hours ago)
1113 attacks on password/key grabbing URLs, env grabbing URLs (type 2), shell probes, env grabbing U ...
show more
1113 attacks on password/key grabbing URLs, env grabbing URLs (type 2), shell probes, env grabbing URLs, config grabbing URLs (type 2), VC URLs, directory traversals, PHP URLs:
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /%2e%2e/.env HTTP/1.1
GET /app-config.json HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
WellSpring
2026-10-09 03:33:52
(1 day ago)
good bot honeypot on tableoftheround.org/@fs/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 03:33:38
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.90.23.235 (235.23.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.23.235 (235.23.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:33:34.618122 2026] [security2:error] [pid 25997:tid 25997] [client 136.90.23.235:45006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tableman2.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tableman2.com"] [uri "/z9x8c7v6b5-debug-trigger-tableman2.com"] [unique_id "ashgjvWy_2aFDchzFogSBgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-09 02:54:45
(1 day ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-09 02:05:17
(1 day ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-10-09 00:07:10
(1 day ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 23:53:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.90.23.235 (235.23.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.23.235 (235.23.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:53:42.457206 2026] [security2:error] [pid 17472:tid 17472] [client 136.90.23.235:41048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||szeliga.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "szeliga.com"] [uri "/z9x8c7v6b5-debug-trigger-szeliga.com"] [unique_id "asgtBh0r0EIXkHqEovih9wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-08 23:17:49
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:06:27
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.90.23.235 (235.23.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.23.235 (235.23.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:06:23.856901 2026] [security2:error] [pid 21645:tid 21645] [client 136.90.23.235:52832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||syscoxlegends.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "syscoxlegends.com"] [uri "/z9x8c7v6b5-debug-trigger-syscoxlegends.com"] [unique_id "asgh73jF3qD8XOJkP9uMLgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-10-08 23:04:50
(1 day ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-7)
show less
Bad Web Bot
๐ง๐ท
radardatelecom
2026-10-08 22:27:07
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:07:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.90.23.235 (235.23.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.23.235 (235.23.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:07:41.838614 2026] [security2:error] [pid 30721:tid 30721] [client 136.90.23.235:53918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "synergystudios.org"] [uri "/dist../.env"] [unique_id "asgULR6d4lOj6lCak-6rJAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Secure Gatewayยฎ๏ธ
2026-10-08 22:00:33
(1 day ago)
Report By Secure Gateway Security Team: SQL Injection Attempt Detected
Hacking
๐บ๐ธ
ALSCOยฎ๏ธ
2026-10-08 22:00:33
(1 day ago)
Report By ALSCO Security Team: XSS Injection Attempt Detected
Web App Attack