๐ฉ๐ช
ger-stg-sifi1
2026-07-30 00:32:51
(9 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
paissangroup
2026-07-29 23:01:21
(10 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 19:45:33
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.33.179.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.33.179.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 15:45:29.142060 2026] [security2:error] [pid 210630:tid 210630] [client 162.33.179.56:42046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qbasys.com.grdigitaldesigns.com"] [uri "/.env"] [unique_id "ampYWWncNQp4VhZOBgyDdAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski
2026-07-29 18:27:38
(15 hours ago)
IVski WAF | Sensitive file probe detected - looking for .env
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-29 16:09:41
(17 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 162.33.179.56 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 162.33.179.56 (US/United States/Illinois/Chicago/-)
show less
Bad Web Bot
Anonymous
2026-07-29 16:07:22
(17 hours ago)
162.33.179.56 - - [29/Jul/2026:18:07:21 +0200] "GET /.env HTTP/1.1" 403 5496 "-" "Mozilla/5.0 AppleW ...
show more
162.33.179.56 - - [29/Jul/2026:18:07:21 +0200] "GET /.env HTTP/1.1" 403 5496 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.1; +https://openai.com/gptbot"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-07-29 15:47:32
(17 hours ago)
Login credentials theft attempt
Hacking
Anonymous
2026-07-29 15:45:01
(18 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 15:26:08
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.33.179.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.33.179.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 11:26:03.542621 2026] [security2:error] [pid 3033301:tid 3033301] [client 162.33.179.56:39478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mrobertdesignbuild.com.globalsolutions.technology"] [uri "/.env"] [unique_id "amobi5_iG2hMPgZLAdS2VwAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 14:23:05
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.33.179.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.33.179.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 10:22:59.201751 2026] [security2:error] [pid 798997:tid 798997] [client 162.33.179.56:38908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pjv.us.pjvcds.com"] [uri "/.env"] [unique_id "amoMw6Ii2x2ieaCArckYfgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 12:24:20
(21 hours ago)
162.33.179.56 - - [29/Jul/2026:12:24:19 +0000] "GET /.env HTTP/1.1" 403 153 "-" "Mozilla/5.0 AppleWe ...
show more
162.33.179.56 - - [29/Jul/2026:12:24:19 +0000] "GET /.env HTTP/1.1" 403 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.1; +https://openai.com/gptbot" "-" "exhunter.schmittel-it.com"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 11:42:08
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 162.33.179.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.33.179.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 07:42:03.564060 2026] [security2:error] [pid 366802:tid 366807] [client 162.33.179.56:53964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.windstream-sales.com"] [uri "/.env"] [unique_id "amnnCyNSN8qi-zhMaZeXYwAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-07-29 11:26:52
(22 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-stl2-14)
Hacking
Web App Attack
๐ฌ๐ง
systems
2023-07-21 09:32:10
(3 years ago)
Brute Force
Hacking
Anonymous
2023-07-21 08:15:14
(3 years ago)
brute force VPN attempts
VPN IP
Brute-Force