๐บ๐ธ
TPI-Abuse
2026-10-02 05:30:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:30:19.389604 2026] [security2:error] [pid 10120:tid 10156] [client 185.137.93.172:62984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.84"] [uri "/.env"] [unique_id "ar9Bazi2KoR3d5SjFAbRQwAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-10-02 04:57:48
(1 day ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-5)
Hacking
Bad Web Bot
๐ณ๐ฑ
DrLex0
2026-10-02 04:31:23
(1 day ago)
POST on root path and poking for .env files, A TRUE CLASSIC.
185.137.93.172 80 - [02/Oct/2026:04:31 ...
show more
POST on root path and poking for .env files, A TRUE CLASSIC.
185.137.93.172 80 - [02/Oct/2026:04:31:23 +0000] "GET /.env HTTP/1.1" 404 2439 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
185.137.93.172 80 - [02/Oct/2026:04:31:23 +0000] "POST / HTTP/1.1" 400 528 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
185.137.93.172 443 - [02/Oct/2026:04:31:23 +0000] "GET /.env HTTP/1.1" 404 7508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
185.137.93.172 443 - [02/Oct/2026:04:31:23 +0000] "POST / HTTP/1.1" 400 5412 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 04:15:35
(1 day ago)
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 04:12:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 00:12:23.515042 2026] [security2:error] [pid 10263:tid 10263] [client 185.137.93.172:61801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.137"] [uri "/.env"] [unique_id "ar8vJ3wKTu0RSYCY-dRmRgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 02:41:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:40:56.822257 2026] [security2:error] [pid 18339:tid 18339] [client 185.137.93.172:60340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.147"] [uri "/.env"] [unique_id "ar8ZuJN6RTkzsa0sfRzf8wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 02:04:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:04:09.012788 2026] [security2:error] [pid 22316:tid 22339] [client 185.137.93.172:60538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.14"] [uri "/.env"] [unique_id "ar8RGVyvR4Cc8jT4YV_YbwAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Roper123
2026-10-02 02:02:45
(1 day ago)
Web exploits
Hacking
Web App Attack
Anonymous
2026-10-02 01:58:12
(1 day ago)
185.137.93.172 - - [02/Oct/2026:01:58:11 +0000] "GET /.env HTTP/1.1" 404 6852 "-" "Mozilla/5.0 (X11; ...
show more
185.137.93.172 - - [02/Oct/2026:01:58:11 +0000] "GET /.env HTTP/1.1" 404 6852 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:48:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:48:49.351439 2026] [security2:error] [pid 21424:tid 21424] [client 185.137.93.172:57316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.92"] [uri "/.env"] [unique_id "ar8NgfKSh0MtrwRNajLrpgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 01:37:58
(1 day ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 185 ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 185.137.93.172 - - \[02/Oct/2026:03:37:43 +0200\] "GET /.env HTTP/1.1" 404 5844 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
regishoussin
2026-10-02 01:34:49
(1 day ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-02 01:34 UTC.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
langenkamp-media
2026-10-02 01:29:16
(1 day ago)
Fail2Ban: Banned from jail nginx-scan-critical on 3dausdu.de
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:22:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.137.93.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:22:14.393737 2026] [security2:error] [pid 10775:tid 10775] [client 185.137.93.172:55357] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.117"] [uri "/.env"] [unique_id "ar8HRgX4R5K3FRVGTlkZlQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-02 01:16:35
(1 day ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 1s
Web App Attack