๐บ๐ธ
xxkodedxx
2026-08-23 14:11:29
(4 hours ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 3ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 3ร edge-block in 10m window.
Origin: US / AS14061 DigitalOcean, LLC
Active: 14:11:07โ14:11:11 UTC
Volume: 3 HTTP req
Probed: /_profiler/phpinfo, /.env, /
Status mix: 444ร3
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 13:48:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.99.237.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.99.237.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:48:08.136699 2026] [security2:error] [pid 30215:tid 30215] [client 167.99.237.238:45456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aivosminerals.com"] [uri "/.env"] [unique_id "aor6GGKINY_bLTIMv0gz8QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-23 08:40:34
(9 hours ago)
[SunAug2310:40:27.1158412026][security2:error][pid2237960:tid2238738][client167.99.237.238:0]ModSecu ...
show more
[SunAug2310:40:27.1158412026][security2:error][pid2237960:tid2238738][client167.99.237.238:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"aidweb.ch\"][uri\"/.env\"][unique_id\"aoqx-9ChV6vLZGNcUt-vMQAAAZQ\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-22 22:04:00
(20 hours ago)
Auto-ban: >3000 req/min op 2026-08-22
Web App Attack
SSH
Hacking
๐ฆ๐บ
2000cn.com.au
2026-08-22 20:00:48
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ต๐ฑ
Budyn
2026-08-22 13:53:03
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.sweetpuddingtrap.online | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-08-22 13:05:08
(1 day ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-22 06:08:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.99.237.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.99.237.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:08:30.455047 2026] [security2:error] [pid 22959:tid 22959] [client 167.99.237.238:58474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "admin.cmabiblequizzing.org"] [uri "/.env"] [unique_id "aok83mnu7gpq5BOMfnbGRgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-22 04:41:20
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.astropot.online | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-22 02:35:07
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-08-22 00:15:01
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 21:06:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.99.237.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.99.237.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:06:18.551726 2026] [security2:error] [pid 3013:tid 3018] [client 167.99.237.238:47582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aaenroll.com"] [uri "/.env"] [unique_id "aoi9yvDRmXDjYPsjcVmCvAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 20:47:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.99.237.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.99.237.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 16:47:38.864881 2026] [security2:error] [pid 9876:tid 9876] [client 167.99.237.238:33600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aacon-ags.com"] [uri "/.env"] [unique_id "aoi5aonTXmZlnyCEuHJ0_QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-29 06:05:53
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-06-29 05:30:06
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack