๐จ๐ฆ
polycoda
2025-05-27 19:27:41
(1 year ago)
๐ Probes for tons of inexistent files and PHP scripts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-26 23:57:20
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 196.127.141.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 196.127.141.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 26 19:57:13.882372 2025] [security2:error] [pid 1258110:tid 1258110] [client 196.127.141.232:56889] [client 196.127.141.232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "learningbyshipping.com"] [uri "/.env"] [unique_id "aDT_2dv_T5dsLEy5dglx8wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-26 23:50:07
(1 year ago)
Fail2ban block
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
Bedios GmbH
2025-05-26 22:30:42
(1 year ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2025-05-26 22:18:19
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 196.127.141.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 196.127.141.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 26 18:18:12.610155 2025] [security2:error] [pid 1585215:tid 1585215] [client 196.127.141.232:65383] [client 196.127.141.232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "businessvaluationapp.com"] [uri "/.env"] [unique_id "aDTopIvrTylOpm9w3dSwVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-05-26 19:49:18
(1 year ago)
Cloudflare WAF: Request Path: /.env Request Query: Host: elhacker.net userAgent: ZAKREGEX-Scanner/2 ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: elhacker.net userAgent: ZAKREGEX-Scanner/2.3.2 Action: block Source: firewallManaged ASN Description: ASMedi Country: MA Method: GET Timestamp: 2025-05-26T19:49:18Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-05-26 19:25:09
(1 year ago)
nginx-alfa-240
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-05-26 18:32:24
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
rdpguard.com
2025-05-26 10:24:56
(1 year ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-05-26 10:11:58
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 196.127.141.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 196.127.141.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 26 06:11:53.462787 2025] [security2:error] [pid 2714494:tid 2714494] [client 196.127.141.232:59582] [client 196.127.141.232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theledman.com"] [uri "/.env"] [unique_id "aDQ-aVy57n8z8fUm4MTvBQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
joecaliber
2025-05-26 09:40:02
(1 year ago)
Malicious activity detected by monitoring system. Attack types observed: LFI SCAN.
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-26 07:51:05
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 196.127.141.232 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 196.127.141.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 26 03:50:59.134950 2025] [security2:error] [pid 1057071:tid 1057071] [client 196.127.141.232:62515] [client 196.127.141.232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proprocessor.com"] [uri "/.env"] [unique_id "aDQdY7ifjrWQUk1rPxzf-QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2025-05-26 07:35:01
(1 year ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2025-05-26 07:30:51
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ง๐ช
cmbplf
2025-05-26 04:23:14
(1 year ago)
114 requests with url.path *.env
Brute-Force
Bad Web Bot