🇩🇪
paissangroup
2026-09-12 08:38:35
(24 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:24:10
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 18.143.164.20 (ec2-18-143-164-20.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 18.143.164.20 (ec2-18-143-164-20.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:24:06.568536 2026] [security2:error] [pid 5459:tid 5459] [client 18.143.164.20:65313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifestylemedica.com"] [uri "/.env.local"] [unique_id "aqUMJvFBE6coWzNXD6o_rwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
RoboSOC
2026-09-12 07:56:16
(1 hour ago)
phpunit Remote Code Execution Vulnerability, PTR: ec2-18-143-164-20.ap-southeast-1.compute.amazonaws ...
show more
phpunit Remote Code Execution Vulnerability, PTR: ec2-18-143-164-20.ap-southeast-1.compute.amazonaws.com.
show less
Hacking
🇳🇱
Alt255
2026-09-12 07:39:31
(1 hour ago)
18.143.164.20 - - \[12/Sep/2026:09:39:29 +0200\] "GET /.env.local HTTP/1.1" 404 28987 "-" "Mozilla/5 ...
show more
18.143.164.20 - - \[12/Sep/2026:09:39:29 +0200\] "GET /.env.local HTTP/1.1" 404 28987 "-" "Mozilla/5.0 \(Linux\; U\; Android 4.4.2\; en-US\; HM NOTE 1W Build/KOT49H\) AppleWebKit/534.30 \(KHTML, like Gecko\) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 07:39:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 18.143.164.20 (ec2-18-143-164-20.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 18.143.164.20 (ec2-18-143-164-20.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:39:09.753642 2026] [security2:error] [pid 7097:tid 7097] [client 18.143.164.20:49566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.backtosleep.com"] [uri "/.env.local"] [unique_id "aqUBneN0LMK9iuGgFbJAxgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-12 07:35:01
(1 hour ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-12 07:18:10
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 07:14:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 18.143.164.20 (ec2-18-143-164-20.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 18.143.164.20 (ec2-18-143-164-20.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:14:07.592485 2026] [security2:error] [pid 10380:tid 10380] [client 18.143.164.20:56057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.andrejblatnik.com"] [uri "/.env.local"] [unique_id "aqT7v879ZAX1K7Ek6BLkOAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-12 06:54:43
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 18.143.164.20 (SG/Singapore/ec2-18-143-1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 18.143.164.20 (SG/Singapore/ec2-18-143-164-20.ap-southeast-1.compute.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 18.143.164.20 - - [12/Sep/2026:08:54:39 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 403 146 "-" "python-requests/2.34.2" "-" host=www.pegasoadv.it
show less
Port Scan
🇧🇪
cmbplf
2026-09-12 05:29:09
(3 hours ago)
165 requests with url.path /phpinfo.php
163 requests with url.path /vendor/phpunit/phpunit/src/Uti ...
show more
165 requests with url.path /phpinfo.php
163 requests with url.path /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 05:28:22
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.143.164.20 (ec2-18-143-164-20.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 18.143.164.20 (ec2-18-143-164-20.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:28:17.267400 2026] [security2:error] [pid 2543:tid 2543] [client 18.143.164.20:63593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "savoiapower.com"] [uri "/.env"] [unique_id "aqTi8WMRe84912IrRW0uEwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Phenix Info
2026-09-12 04:16:47
(4 hours ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
🇹🇷
ycoskun41
2026-09-12 03:39:01
(5 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
Anonymous
2026-09-12 03:35:29
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-12 03:25:02
(5 hours ago)
crowdsecurity/CVE-2017-9841
Brute-Force
Web App Attack