πΊπΈ
craudiovizai
2026-09-25 18:30:31
(17 hours ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /?%3Cplay%3Ewithme%3C ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /?%3Cplay%3Ewithme%3C%2F%3E=, /.env. Blocked at the edge.
show less
Bad Web Bot
πΊπΈ
mnsf
2026-09-25 16:05:19
(20 hours ago)
Abuse Detected (12)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-25 15:26:03
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 11:25:59.591039 2026] [security2:error] [pid 664:tid 664] [client 150.251.225.244:27209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kh6jim.com"] [uri "/.env"] [unique_id "araSh_RYG2nFDgPW6TtWxQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-25 14:56:09
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 10:56:05.145839 2026] [security2:error] [pid 11380:tid 11380] [client 150.251.225.244:54799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edemahy.com"] [uri "/.env"] [unique_id "araLhW397FH5K-01BHI5GwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
2000cn.com.au
2026-09-25 14:03:56
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-25 14:00:05
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 09:59:58.872388 2026] [security2:error] [pid 15365:tid 15365] [client 150.251.225.244:29943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandhage.com"] [uri "/.env"] [unique_id "arZ-XtqezQWAHdgMw50k6gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 22:46:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 18:46:12.490334 2026] [security2:error] [pid 28118:tid 28118] [client 150.251.225.244:43875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jwphotodesign.com"] [uri "/.env"] [unique_id "arWoNAfI_0mXUWUM5GrsUQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-24 21:59:58
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-24
Web App Attack
SSH
Hacking
π©πͺ
FeG Deutschland
2026-09-24 21:56:02
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π³π±
Alt255
2026-09-24 21:48:46
(1 day ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 150.251.225.244 - - [24/Sep/2026:23:48:29 +0200] "GET /.env HTTP/1.1" 404 112317 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 21:42:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 17:42:50.254417 2026] [security2:error] [pid 8277:tid 8277] [client 150.251.225.244:23819] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airdriedrivingschool.com"] [uri "/.env"] [unique_id "arWZWvJQjZV21js07qIp4QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 21:18:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 150.251.225.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 17:17:57.521820 2026] [security2:error] [pid 13278:tid 13278] [client 150.251.225.244:34369] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kampinenlaw.com"] [uri "/.env"] [unique_id "arWThR9-MVVDorp33OH4AQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 21:00:01
(1 day ago)
suspicious request in access.log
Web App Attack
π©πͺ
Bedios GmbH
2026-09-24 20:36:15
(1 day ago)
Login credentials theft attempt
Hacking
π¦πΊ
crispi
2026-09-24 20:33:51
(1 day ago)
Port scan from 150.251.225.244
Port Scan