Anonymous
2026-09-01 20:26:16
(1 hour ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
π©πͺ
LRob
2026-09-01 18:53:47
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-09-01 18:53 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 17:56:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:56:28.769038 2026] [security2:error] [pid 31889:tid 31889] [client 155.2.219.197:56112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csme-eprr.com"] [uri "/.git/HEAD"] [unique_id "apcRzNOPrKjN497vJiSr9QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅πΎ
armandosaucedo.me
2026-09-01 16:33:42
(5 hours ago)
Threat Intelligence via ARMTI, Web Attack: GET /.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 15:50:16
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 11:50:10.881036 2026] [security2:error] [pid 32694:tid 32694] [client 155.2.219.197:60850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crucialpins.com"] [uri "/.git/HEAD"] [unique_id "apb0Mr8SIJNFJkEf8hF9gwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 15:11:25
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 11:11:21.145802 2026] [security2:error] [pid 7888:tid 7888] [client 155.2.219.197:44504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crowmoonmarketing.com"] [uri "/.env"] [unique_id "apbrGWTp8kF-Y2EFLy5HvAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 13:48:11
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:48:04.968119 2026] [security2:error] [pid 19488:tid 19488] [client 155.2.219.197:36086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "criticalmassofficial.com"] [uri "/.env"] [unique_id "apbXlLTYXqZGBL_Qn9TR7QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 12:37:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:37:51.386522 2026] [security2:error] [pid 20789:tid 20789] [client 155.2.219.197:40906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cressyvideo.com"] [uri "/.git/HEAD"] [unique_id "apbHHy6qy7NgyPyKv5yj8wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 12:10:55
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:10:52.055088 2026] [security2:error] [pid 20285:tid 20285] [client 155.2.219.197:56378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creeation.com"] [uri "/.env"] [unique_id "apbAzAFIN7oNToRO3H2F2QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 11:46:35
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:46:30.970540 2026] [security2:error] [pid 759130:tid 759154] [client 155.2.219.197:52558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "credit-card-cap.com"] [uri "/.env"] [unique_id "apa7Fnf7tZ9OWwz5i2jGggAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:26:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:26:26.988959 2026] [security2:error] [pid 4562:tid 4562] [client 155.2.219.197:41672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crearetest.com"] [uri "/.env"] [unique_id "apaoUrQViI-CnCw9viW7wQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 09:59:14
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 155.2.219.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:59:08.093787 2026] [security2:error] [pid 3054:tid 3054] [client 155.2.219.197:45754] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "crazycontrols.com"] [uri "/.git/HEAD"] [unique_id "apah7BMJ8miHklYja1z4TwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-09-01 09:34:44
(12 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
πΊπΈ
mnsf
2026-09-01 09:05:28
(12 hours ago)
Abuse Detected (16)
Brute-Force
Web App Attack
π«π·
ecode hosting
2026-09-01 07:02:04
(14 hours ago)
Domain : cozumdoktoru.com
Rule : config
2026-09-01 06:36:54 10.100.1.20 GET /.git/HEAD - 443 - 172.7 ...
show more
Domain : cozumdoktoru.com
Rule : config
2026-09-01 06:36:54 10.100.1.20 GET /.git/HEAD - 443 - 172.71.238.114 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15 - cozumdoktoru.com 404 8 0 1396 726 1708 - 155.2.219.197
show less
Hacking
SQL Injection