๐ฎ๐ช
AutosOnShow
2026-10-02 11:37:04
(20 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-10-02 11:36:25.694 |
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:30:50
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 194.5.49.62 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.49.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:30:42.138093 2026] [security2:error] [pid 21108:tid 21108] [client 194.5.49.62:50905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.22"] [uri "/.env"] [unique_id "ar-V4o-ovWUI-Wf87Ek4UQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:14:16
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 194.5.49.62 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.49.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:14:08.395275 2026] [security2:error] [pid 21674:tid 21674] [client 194.5.49.62:44773] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.37"] [uri "/.env"] [unique_id "ar-SAE6dt3lhdmmSsw0cegAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
Peter Yu
2026-10-02 10:55:34
(21 hours ago)
Bad Web Bot
Web App Attack
๐ฉ๐ช
mist x
2026-09-25 08:07:04
(1 week ago)
Honeypot Web Sensor: Malicious HTTP scanner probe targeting sensitive path: POST / HTTP/1.1
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 08:04:00
(1 week ago)
[ns65.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env
Hacking
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-09-25 07:49:17
(1 week ago)
connection to honeypot
Email Spam
Port Scan
๐ฉ๐ช
Tamsy
2026-09-25 07:44:14
(1 week ago)
HTTPD - 4xx scan
Web App Attack
๐ง๐ท
Vieira Filho
2026-09-24 20:11:40
(1 week ago)
194.5.49.62 - - [24/Sep/2026:17:11:39 -0300] [35.198.31.82] "35.198.31.82" "GET /.env HTTP/1.1" 404 ...
show more
194.5.49.62 - - [24/Sep/2026:17:11:39 -0300] [35.198.31.82] "35.198.31.82" "GET /.env HTTP/1.1" 404 571 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 0.000
...
show less
Brute-Force
Web App Attack
Exploited Host
๐บ๐ธ
Starburst SysOp Team
2026-09-24 20:10:49
(1 week ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-iad5-2)
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 20:08:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.5.49.62 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 194.5.49.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:08:06.936191 2026] [security2:error] [pid 22174:tid 22189] [client 194.5.49.62:38355] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.44"] [uri "/.env"] [unique_id "arWDJhqM1KPVB_LZcxvknAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-03 00:50:13
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2026-09-03 00:20:51
(1 month ago)
2026/09/03 02:20:50 [error] 3328#261642: *2105292 limiting requests, excess: 0.997 by zone "crawler" ...
show more
2026/09/03 02:20:50 [error] 3328#261642: *2105292 limiting requests, excess: 0.997 by zone "crawler", client: 194.5.49.62, server: ksol.io, request: "GET /.git/config?__goaway_challenge=cookie&__goaway_id=2a33d3c8adbef997ac79f38da193e16b&__goaway_referer=http%3A%2F%2Fksol.io%2F.git%2Fconfig HTTP/1.1", host: "ksol.io", referrer: "https://ksol.io/.git/config"
...
show less
Bad Web Bot
๐ซ๐ท
conseilgouz
2026-09-01 00:19:16
(1 month ago)
joe-Direct access to plugin not allowed.
Hacking
Anonymous
2026-09-01 00:12:40
(1 month ago)
[ns67.kdns.gr] httpd-config-scan: sites=kdns.gr; logs=/var/www/vhosts/kdns.gr/logs/access_log,/var/w ...
show more
[ns67.kdns.gr] httpd-config-scan: sites=kdns.gr; logs=/var/www/vhosts/kdns.gr/logs/access_log,/var/www/vhosts/system/kdns.gr/logs/access_log; samples=/.git/config
show less
Hacking
Web App Attack