Anonymous
2025-10-17 06:28:22
(11 months ago)
suspicious paths in IIS
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-10-12 21:59:05
(11 months ago)
Auto-ban: >500 bad req/min on 2025-10-11
Hacking
Web App Attack
SSH
๐น๐ท
rtbh.com.tr
2025-10-12 20:09:19
(11 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ณ๐ฑ
BlueWire Hosting
2025-10-12 04:10:17
(11 months ago)
Probing for application vulnerabilities
Brute-Force
Web App Attack
๐ณ๐ฑ
jjnxpct
2025-10-12 03:45:08
(11 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env (Rule ID: 210492)
show less
Hacking
Web App Attack
Anonymous
2025-10-12 02:44:24
(11 months ago)
Try to connect to Port_Scan_443_stealth
Port Scan
Anonymous
2025-10-12 01:12:32
(11 months ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-12 01:05:22
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 197.238.13.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 197.238.13.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 21:05:17.101457 2025] [security2:error] [pid 10920:tid 10920] [client 197.238.13.235:55253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "testo.bwill.dev"] [uri "/.env"] [unique_id "aOr-zcEebp2nehq2Tm_pMQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-10-12 00:09:18
(11 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-11 23:17:43
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 197.238.13.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 197.238.13.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 19:17:39.032456 2025] [security2:error] [pid 16406:tid 16406] [client 197.238.13.235:57569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stringview.com"] [uri "/.env"] [unique_id "aOrlkxFwk2Y8gDrJSu_4dAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tr1n
2025-10-11 23:02:58
(11 months ago)
Triggered Cloudflare WAF (firewallCustom) from TN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from TN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
jcbriar
2025-10-11 22:58:57
(11 months ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-11 22:52:06
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 197.238.13.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 197.238.13.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 18:52:01.099934 2025] [security2:error] [pid 7388:tid 7388] [client 197.238.13.235:51779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stansco.com"] [uri "/.env"] [unique_id "aOrfken7sOaLfuHWy0-baQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-10-11 20:09:18
(11 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-11 19:13:02
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 197.238.13.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 197.238.13.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 15:12:55.057677 2025] [security2:error] [pid 21395:tid 21395] [client 197.238.13.235:58653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roughexports.com"] [uri "/.env"] [unique_id "aOqsN4O-ZwqWbCaAm-jocAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack