๐จ๐ญ
backslash
2026-07-20 08:39:00
(4 hours ago)
Web App Attack
Anonymous
2026-07-19 16:05:39
(21 hours ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (12/60 min)'; Requests=12
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-19 15:09:09
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.89.154.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.89.154.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 11:09:02.253310 2026] [security2:error] [pid 1755267:tid 1755267] [client 196.89.154.233:53178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konahawaii.com"] [uri "/.env"] [unique_id "alzojsbByfp1ilqQkhq0TgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-07-19 14:50:16
(22 hours ago)
2026/07/19 14:50:15 [error] 1088628#1088628: *2196048 FastCGI sent in stderr: "Primary script unknow ...
show more
2026/07/19 14:50:15 [error] 1088628#1088628: *2196048 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 196.89.154.233, server: kocerroxy.com, request: "GET /info.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "app.kocerroxy.com"
2026/07/19 14:50:15 [error] 1088628#1088628: *2196047 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 196.89.154.233, server: kocerroxy.com, request: "GET /info.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
2026/07/19 14:50:15 [error] 1088628#1088628: *2196047 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 196.89.154.233, server: kocerroxy.com, request: "GET /test.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
196.89.154.233
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 14:45:28
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.89.154.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.89.154.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 10:45:20.938057 2026] [security2:error] [pid 23787:tid 23787] [client 196.89.154.233:64631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knoxvillelimos.com"] [uri "/.env"] [unique_id "alzjAFDZvBU_GJHpKa3yLgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-19 14:38:57
(22 hours ago)
196.89.154.233 - - [19/Jul/2026:10:38:57 -0400] "GET /phpinfo.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
196.89.154.233 - - [19/Jul/2026:10:38:57 -0400] "GET /phpinfo.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; rv:126.0) Gecko/20100101 Firefox/126.0"
196.89.154.233 - - [19/Jul/2026:10:38:57 -0400] "GET /info.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
196.89.154.233 - - [19/Jul/2026:10:38:57 -0400] "GET /test.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
...
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-19 14:27:28
(23 hours ago)
Try to access /.env
Web App Attack
๐บ๐ธ
kosada.com
2026-07-19 14:25:08
(23 hours ago)
Web vulnerability probing: /phpinfo.php
Web App Attack
๐จ๐ญ
4server
2026-07-19 14:22:08
(23 hours ago)
[SunJul1916:22:04.3241502026][security2:error][pid1413752:tid1413981][client196.89.154.233:0]ModSecu ...
show more
[SunJul1916:22:04.3241502026][security2:error][pid1413752:tid1413981][client196.89.154.233:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"[\\\\\\\\n\\\\\\\\r]\"atARGS_GET:lang.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"143\"][id\"390722\"][rev\"5\"][msg\"Atomicorp.comWAFRules:HTTPHeaderInjectionAttackviapayload\(CR/LFdetected\)\"][data\"MatchedData:\\\\x0dfoundwithinARGS_GET:lang:jaVasCript:/\*-/\*/\`/\'/\\\\x5c\\\\x22/\*\*/\(/\*/oNcliCk=confirm\(\'https://www.google.com/search\?q=1\'\)\)//\\\\x0d\\\\x0a\\\\x0d\\\\x0a//\</stYle/\</titLe/\</teXtarEa/\</scRipt/--\!\>\\\\x5c\\\\x5cx3csVg/\<sVg/oNloAd=confirm\(\'https://www.google.com/search\?q=1\'\)//\>\\\\x5c\\\\x5cx3e\"][severity\"CRITICAL\"][hostname\"whatsdecor.ch\"][uri\"/prodotto/12622/\"][unique_id\"alzdjNuySTEGf-RZC4ZA2AAAARU\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-07-19 14:17:21
(23 hours ago)
SQL injection attempt
SQL Injection
๐ซ๐ท
pm33
2026-07-19 14:09:33
(23 hours ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐ฆ๐บ
Telemetry2U.com
2026-07-19 14:07:17
(23 hours ago)
SQL Injection attempt detected
Web App Attack
SQL Injection
๐บ๐ธ
mnsf
2026-07-19 14:05:29
(23 hours ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 13:58:34
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.89.154.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.89.154.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 09:58:26.611208 2026] [security2:error] [pid 3058673:tid 3058673] [client 196.89.154.233:52574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirkrmartin.com"] [uri "/.env"] [unique_id "alzYAgufTHsAL6ZVQUNIHQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 13:42:55
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.89.154.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.89.154.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 09:42:50.919807 2026] [security2:error] [pid 24073:tid 24073] [client 196.89.154.233:63878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingdomvalleyfarm.com"] [uri "/.env"] [unique_id "alzUWgOp0aS92nMX8z0rPQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack