๐บ๐ธ
TPI-Abuse
2026-10-02 17:04:22
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 170.64.231.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.231.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:04:17.245817 2026] [security2:error] [pid 20794:tid 20794] [client 170.64.231.2:28698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bawaselcenter.iahksa.com"] [uri "/.env"] [unique_id "ar_kERTOVdJdJScNAjlD-gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-10-02 17:00:59
(15 minutes ago)
Environment file probe
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-02 16:57:05
(19 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-10-02 16:49:22
(26 minutes ago)
Malicious activity from IP detected: crowdsecurity/CVE-2017-9841.
Web App Attack
๐ฉ๐ช
Nevermind
2026-10-02 16:48:53
(27 minutes ago)
170.64.231.2 - - [02/Oct/2026:18:48:52 +0200] "GET /.env HTTP/1.1" 403 6285 "-" "Mozilla/5.0 (Window ...
show more
170.64.231.2 - - [02/Oct/2026:18:48:52 +0200] "GET /.env HTTP/1.1" 403 6285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
170.64.231.2 - - [02/Oct/2026:18:48:52 +0200] "GET /.git/config HTTP/1.1" 403 6285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
170.64.231.2 - - [02/Oct/2026:18:48:52 +0200] "GET /vendor/laravel-filemanager/js/script.js HTTP/1.1" 404 6298 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
170.64.231.2 - - [02/Oct/2026:18:48:52 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 6298 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-02 16:38:06
(38 minutes ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฉ๐ช
HERA - Operations
2026-10-02 16:34:30
(41 minutes ago)
bau-arge - searching for vulnerable scripts: eval-stdin.php 2026/10/02 18:34:29
Web App Attack
๐ฉ๐ช
Holger
2026-10-02 16:28:00
(48 minutes ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ซ๐ท
Little Iguana
2026-10-02 16:06:20
(1 hour ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
Anonymous
2026-10-02 16:05:53
(1 hour ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=28
Hacking
Anonymous
2026-10-02 16:00:02
(1 hour ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:58:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 170.64.231.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.231.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:58:11.535419 2026] [security2:error] [pid 9825:tid 9825] [client 170.64.231.2:14104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batchovens.net"] [uri "/.env"] [unique_id "ar_Uk6u6RIePfuBGlmGlOAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-02 15:52:18
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
๐ซ๐ท
Quarks Solutions
2026-10-02 15:49:19
(1 hour ago)
crowdsecurity/appsec-vpatch
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:39:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 170.64.231.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.231.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:39:41.157889 2026] [security2:error] [pid 23244:tid 23244] [client 170.64.231.2:25230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bassboatmagazine.com"] [uri "/.env"] [unique_id "ar_QPW7XeEwxfdoeuey1dwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack