๐ฉ๐ช
FeG Deutschland
2026-08-26 04:04:26
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-25 22:02:26
(14 hours ago)
Auto-ban: >3000 req/min op 2026-08-25
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-25 11:49:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:49:05.197697 2026] [security2:error] [pid 29666:tid 29666] [client 176.9.39.62:54850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adamfogel.com"] [uri "/.env"] [unique_id "ao2BMUOi6dkSY0pqZG9u9QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-25 10:22:47
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 176.9.39.62 (DE/Germany/shde-2ad57. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 176.9.39.62 (DE/Germany/shde-2ad57.serverlet.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:11:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:10:58.266403 2026] [security2:error] [pid 7024:tid 7024] [client 176.9.39.62:39232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.formationone.com"] [uri "/.env"] [unique_id "ao1qMih8mynJuQKHn2IMrAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
daveoctober
2026-08-25 04:33:06
(1 day ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-25 04:23:46
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-08-25 04:23 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 04:06:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 00:06:04.990732 2026] [security2:error] [pid 23013:tid 23013] [client 176.9.39.62:55136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lhhs69.org"] [uri "/.env"] [unique_id "ao0UrDnlUNHTZGHVkwAMGQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-25 04:05:32
(1 day ago)
Accessed trap at '/.env'
Web App Attack
๐ท๐บ
DZBOT
2026-08-25 04:01:39
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-08-25 01:32:12
(1 day ago)
Http Port:80 (http_status:404) - Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/6 ...
show more
Http Port:80 (http_status:404) - Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.2 Safari/605.1.15
show less
Web App Attack
Anonymous
2026-08-25 01:05:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 00:39:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 20:39:26.162290 2026] [security2:error] [pid 4994:tid 4994] [client 176.9.39.62:46944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gictd.com"] [uri "/.env"] [unique_id "aozkPg8ePdpnupAiqOYOyQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
foff
2026-08-24 23:54:10
(1 day ago)
Source IP: 176.9.39.62 (DE/Hetzner Online GmbH). Web application attack detected by OWASP CRS (local ...
show more
Source IP: 176.9.39.62 (DE/Hetzner Online GmbH). Web application attack detected by OWASP CRS (local file inclusion). Attack observed 2026-08-25T09:54:10+10:00.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 23:49:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 176.9.39.62 (shde-2ad57.serverlet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 19:49:04.379507 2026] [security2:error] [pid 6290:tid 6375] [client 176.9.39.62:39022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hkyiquan.org"] [uri "/.env"] [unique_id "aozYcKKRHS_JJM_TS3fhYgAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack