๐ง๐ช
sid3windr
2026-08-21 15:16:07
(1 day ago)
GET /.env (Tarpitted for 1d15h8m27s, wasted 8.06MB)
Web App Attack
๐ง๐ช
sid3windr
2026-08-21 12:09:36
(1 day ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-20 12:11:46
(2 days ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ณ๐ฟ
FaB Property Group
2026-08-20 06:29:50
(2 days ago)
Requested file: owa/
Web App Attack
๐ณ๐ฟ
FaB Property Group
2026-08-20 06:29:50
(2 days ago)
Requested file: owa/
Web App Attack
Anonymous
2026-08-20 00:40:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
itsolon
2026-08-20 00:26:05
(2 days ago)
[20/Aug/2026:02:26:05 +0200] 178718556571.100114 146.70.45.166 33698 217.154.7.177 443
[20/Aug/2026: ...
show more
[20/Aug/2026:02:26:05 +0200] 178718556571.100114 146.70.45.166 33698 217.154.7.177 443
[20/Aug/2026:02:26:05 +0200] 178718556515.482979 146.70.45.166 0 217.154.7.177 443
[20/Aug/2026:02:26:05 +0200] 178718556547.755288 146.70.45.166 0 217.154.7.177 443
[20/Aug/2026:02:26:05 +0200] 178718556592.995246 146.70.45.166 33704 217.154.7.177 443
[20/Aug/2026:02:26:05 +0200] 178718556590.869731 146.70.45.166 33748 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-20 00:19:22
(2 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:16:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 146.70.45.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.45.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:16:29.913216 2026] [security2:error] [pid 20645:tid 20645] [client 146.70.45.166:41628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjtent.com"] [uri "/.env"] [unique_id "aoZHXRVzcWp7HBuPJP9M8QAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-20 00:07:38
(2 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐ณ๐ฑ
Eric
2026-08-20 00:03:48
(2 days ago)
[Thu Aug 20 00:03:40.457418 2026] [security2:error] [pid 4001601:tid 4001601] [client 146.70.45.166: ...
show more
[Thu Aug 20 00:03:40.457418 2026] [security2:error] [pid 4001601:tid 4001601] [client 146.70.45.166:44312] [client 146.70.45.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.fambus.nl"] [uri "/.env"] [unique_id "aoZEXJkzxiLdDm5IbULDFAAAAAc"]
[Thu Aug 20 00:03:47.489331 2026] [security2:error] [pid 4001603:tid 4001603] [client 146.70.45.166:54186] [client 146.70.45.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [se
...
show less
Hacking
Web App Attack
๐ฌ๐ง
Apache
2026-08-19 23:33:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 146.70.45.166 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.45.166 (US/United States/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ซ๐ท
YF
2026-08-19 23:30:36
(2 days ago)
Environment file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 23:21:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 146.70.45.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.45.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 19:21:38.745068 2026] [security2:error] [pid 7492:tid 7492] [client 146.70.45.166:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ard.global"] [uri "/.env"] [unique_id "aoY6gm5vCcLUKhuyjzOHIgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NerdyMcNerderson
2026-08-19 22:59:23
(2 days ago)
MarekCloud auto-ban: ENV leak probe: GET /.env
Bad Web Bot
Web App Attack