Anonymous
2026-09-04 09:30:02
(1 hour ago)
suspicious request in access.log
Web App Attack
🇧🇷
dominioz
2026-09-04 07:06:50
(3 hours ago)
2026-09-04 07:06:10 GET /.env - - 161.178.140.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64) ...
show more
2026-09-04 07:06:10 GET /.env - - 161.178.140.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/58.0.3029.110+Safari/537.3 - 301 467
2026-09-04 07:06:11 GET /.env - - 161.178.140.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/58.0.3029.110+Safari/537.3 - 200 6796
2026-09-04 07:06:12 GET /db.sql - - 161.178.140.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/58.0.3029.110+Safari/537.3 - 301 471
2026-09-04 07:06:14 GET /db.sql - - 161.178.140.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/58.0.3029.110+Safari/537.3 - 404 245
...
show less
Web App Attack
🇿🇦
conure.sh
2026-09-04 05:28:21
(5 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 13s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:50:26
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:50:19.474860 2026] [security2:error] [pid 6776:tid 6776] [client 161.178.140.160:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.frogmouthatx.com"] [uri "/.env"] [unique_id "apo_-7ofSYe1cscqQbN7swAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-04 01:00:21
(9 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇿🇦
conure.sh
2026-09-04 00:16:42
(10 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 10s
Web App Attack
🇩🇪
4server
2026-09-03 23:45:32
(10 hours ago)
[FriSep0401:45:29.5799612026][security2:error][pid3574122:tid3574159][client161.178.140.160:0]ModSec ...
show more
[FriSep0401:45:29.5799612026][security2:error][pid3574122:tid3574159][client161.178.140.160:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.aaaa6877.org\"][uri\"/db.sql\"][unique_id\"apoGmRvh1yEJWk2aQyo4gQAAAEE\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:28:58
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:28:50.511159 2026] [security2:error] [pid 14215:tid 14215] [client 161.178.140.160:52312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vespaitaliancafe.com"] [uri "/.env"] [unique_id "apn0omyGiR3Ds2J6Kz4PFQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 17:44:26
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:44:20.673022 2026] [security2:error] [pid 13610:tid 13707] [client 161.178.140.160:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mindgardens.com"] [uri "/.env"] [unique_id "apmx9DQw0ZchTMYjczn0egAAAko"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 17:16:54
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:16:48.780020 2026] [security2:error] [pid 13535:tid 13535] [client 161.178.140.160:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mail-pmg.com"] [uri "/.env"] [unique_id "apmrgCtxLByFbeRlAcKPCgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-03 17:06:34
(17 hours ago)
Aggressive web search of vulnerable pages: /db.sql /dump.sql /database.sql /backup.sql /config/db.sq ...
show more
Aggressive web search of vulnerable pages: /db.sql /dump.sql /database.sql /backup.sql /config/db.sql ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 14:57:55
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.140.160 (ec2-161-178-140-160.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 10:57:47.712882 2026] [security2:error] [pid 30670:tid 30670] [client 161.178.140.160:62516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.technologymoods.com"] [uri "/.env"] [unique_id "apmK6-AGZV44LXSksgmcSwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-03 14:43:36
(19 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.sweetpuddingtrap.xyz | URI: /phpinfo.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-03 14:10:03
(20 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 13:10:03
(21 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack