๐ฆ๐บ
paulshipley.com.au
2026-06-16 12:06:23
(26 minutes ago)
[Tue Jun 16 22:06:22.901845 2026] [security2:error] [pid 247666] [client 172.216.6.143:53944] [clien ...
show more
[Tue Jun 16 22:06:22.901845 2026] [security2:error] [pid 247666] [client 172.216.6.143:53944] [client 172.216.6.143] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/.env"] [unique_id "ajE8Plx4uYC_51mtTLSZPwAAAAs"]
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-16 11:37:56
(55 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 11:35:42
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 172.216.6.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.216.6.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 07:35:38.861894 2026] [security2:error] [pid 12306:tid 12306] [client 172.216.6.143:60098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fattoria-rendena.it"] [uri "/.env"] [unique_id "ajE1CkzOSVqVkSfnR3K0NQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
roxyapi
2026-06-16 11:23:57
(1 hour ago)
Honeypot: automated vulnerability scan / web app attack. Last probe: GET /.env
Web App Attack
Bad Web Bot
๐ฎ๐น
A000Z
2026-06-16 05:39:31
(6 hours ago)
Fail2Ban: 172.216.6.143 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5. ...
show more
Fail2Ban: 172.216.6.143 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Anonymous
2026-06-16 05:05:02
(7 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-16 05:01:36
(7 hours ago)
Try to access /.env
Web App Attack
๐ณ๐ด
jad-abuse
2026-06-16 04:48:25
(7 hours ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. O ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 3 hits.
show less
Web App Attack
๐ฉ๐ช
todix
2026-06-16 04:35:46
(7 hours ago)
Web App Attack Exploid from 172.216.6.143
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 04:02:44
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.216.6.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.216.6.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 00:02:40.216978 2026] [security2:error] [pid 20870:tid 20870] [client 172.216.6.143:33904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darrenj.com"] [uri "/.env"] [unique_id "ajDK4HfINOcdPKIqbsIY-gAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-16 03:58:45
(8 hours ago)
[Tue Jun 16 13:58:43.783161 2026] [security2:error] [pid 204895] [client 172.216.6.143:24776] [clien ...
show more
[Tue Jun 16 13:58:43.783161 2026] [security2:error] [pid 204895] [client 172.216.6.143:24776] [client 172.216.6.143] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.env"] [unique_id "ajDJ882QDbcVY6Hu3dZ3JQAAAAE"]
...
show less
Web App Attack
๐ง๐ท
Halux
2026-06-16 03:35:33
(8 hours ago)
172.216.6.143 Probing protected path or service
Web App Attack
๐บ๐ธ
mnsf
2026-06-16 03:05:55
(9 hours ago)
Abuse Detected (5)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 02:45:54
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.216.6.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.216.6.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 22:45:48.955358 2026] [security2:error] [pid 11847:tid 11847] [client 172.216.6.143:17286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.airtechconsulting.com"] [uri "/.env"] [unique_id "ajC43EE2ATrbQ8DwsoAUbgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-16 02:29:27
(10 hours ago)
[Tue Jun 16 12:29:26.729445 2026] [security2:error] [pid 197530] [client 172.216.6.143:39028] [clien ...
show more
[Tue Jun 16 12:29:26.729445 2026] [security2:error] [pid 197530] [client 172.216.6.143:39028] [client 172.216.6.143] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ccideas.com.au"] [uri "/.env"] [unique_id "ajC1BiWqbOlQruqHlSyRfAAAAAE"]
...
show less
Web App Attack