๐บ๐ธ
TPI-Abuse
2026-10-02 06:10:45
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 190.95.127.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 190.95.127.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 02:10:38.421576 2026] [security2:error] [pid 30877:tid 30877] [client 190.95.127.136:34594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebeesgold.com"] [uri "/.env.txt"] [unique_id "ar9K3vtOKz_ma0lsrtL30gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 05:15:01
(7 hours ago)
suspicious request in access.log
Web App Attack
๐ต๐ฑ
Budyn
2026-10-02 03:25:47
(9 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: elastic.teddypot.space | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-02 03:05:48
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-10-02 01:06:22
(11 hours ago)
[cb-16al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-16al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 190.95.127.136 - - [02/Oct/2026:03:06:19 +0200] "GET /.env.txt HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-10-01 21:30:11
(15 hours ago)
Suspicious URL access.
Web App Attack
๐ซ๐ท
masterguru
2026-10-01 13:24:29
(23 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 06:06:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 190.95.127.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 190.95.127.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:06:41.032208 2026] [security2:error] [pid 17544:tid 17544] [client 190.95.127.136:36174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magnoliahillproductions.com"] [uri "/.git/config"] [unique_id "ar34cdRmG_7ujQDOmjwybQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-10-01 02:42:38
(1 day ago)
190.95.127.136 - - [30/Sep/2026:22:42:37 -0400] "GET /.env HTTP/1.1" 403 344 "-" "Mozilla/5.0 (Windo ...
show more
190.95.127.136 - - [30/Sep/2026:22:42:37 -0400] "GET /.env HTTP/1.1" 403 344 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-01 02:39:56
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 01:51:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 190.95.127.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 190.95.127.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:51:46.430477 2026] [security2:error] [pid 11807:tid 11807] [client 190.95.127.136:39414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "localonlinevisibility.com.needtoorder.us"] [uri "/.git/config"] [unique_id "ar28sq2Q5KE4XoGhvFJ7fgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
cider1725
2026-09-30 19:30:31
(1 day ago)
190.95.127.136 - - [30/Sep/2026:19:30:30 +0000] "GET /.env.backup HTTP/1.1" 444 0 "-" "Mozilla/5.0 ( ...
show more
190.95.127.136 - - [30/Sep/2026:19:30:30 +0000] "GET /.env.backup HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-"
190.95.127.136 - - [30/Sep/2026:19:30:30 +0000] "GET /.git/index HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-"
190.95.127.136 - - [30/Sep/2026:19:30:30 +0000] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-"
...
show less
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-30 18:20:41
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jenkins.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ง๐ท
P1n4
2026-09-30 18:20:30
(1 day ago)
Heimdal IDS auto-block: sensitive_file (score=0.80)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:11:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 190.95.127.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 190.95.127.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:11:06.316847 2026] [security2:error] [pid 7689:tid 7736] [client 190.95.127.136:51338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adetnw.com"] [uri "/.git/config"] [unique_id "arz8WkWyYSgUu6koX03foAAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack