๐ท๐ด
iulianh
2026-05-03 08:52:35
(5 months ago)
80,443
Brute-Force
SSH
๐ณ๐ฑ
0xffffffff
2026-05-03 08:41:52
(5 months ago)
[2026-05-03 11:41:50.132795] [authz_core:error] [pid 506880:tid 132282343503552] [client 198.23.211. ...
show more
[2026-05-03 11:41:50.132795] [authz_core:error] [pid 506880:tid 132282343503552] [client 198.23.211.167:59248] AH01630: client denied by server configuration: /var/www/*/secrets.json , error_notes:config-files , URI:'/secrets.json'
[2026-05-03 11:41:51.097018] [authz_core:error] [pid 506880:tid 132282318317248] [client 198.23.211.167:59294] AH01630: client denied by server configuration: /var/www/*/app , error_notes:config-files , URI:'/app/.env'
[2026-05-03 11:41:51.113101] [authz_core:error] [pid 506881:tid 132281695987392] [client 198.23.211.167:59340] AH01630: client denied by server configuration: /var/www/*/credentials.json , error_notes:config-files , URI:'/credentials.json'
[2026-05-03 11:41:51.113690] [authz_core:error] [pid 506880:tid 132282157323968] [client 198.23.211.167:59274] AH01630: client denied by server configuration: /var/www/*/.env , error_notes:config-files , URI:'/.env'
[2026-05-03 11:41:51.116171] [authz_core:error] [pid 506880:tid 132282148931264] [client 198.23.211.167:59306] AH0163
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-03 08:15:17
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 04:15:13.485554 2026] [security2:error] [pid 4034:tid 4034] [client 198.23.211.167:5114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creekside.biz"] [uri "/.env"] [unique_id "afcEEaPXlLdYMYQhckQuhwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-03 08:05:28
(5 months ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=16
Hacking
๐ฎ๐ณ
Genhost
2026-05-03 08:05:27
(5 months ago)
SCANNING OF PHP SHELL FILES
Brute-Force
SSH
๐ฉ๐ช
4server
2026-05-03 08:00:51
(5 months ago)
[SunMay0310:00:49.9167132026][security2:error][pid2830216:tid2830297][client198.23.211.167:0]ModSecu ...
show more
[SunMay0310:00:49.9167132026][security2:error][pid2830216:tid2830297][client198.23.211.167:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"archi-box.ch\"][uri\"/app/.env\"][unique_id\"afcAsWjKjglwD5cHh0dn8AAAAJM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 07:52:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 03:52:01.107615 2026] [security2:error] [pid 13517:tid 13517] [client 198.23.211.167:42150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.puckerbackbikini.com"] [uri "/.env"] [unique_id "afb-oUk5cdG_L7JpyU5AbgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-03 07:41:41
(5 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 07:09:12
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 03:09:04.086017 2026] [security2:error] [pid 26532:tid 26532] [client 198.23.211.167:39704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.drgracetomastolentino.com"] [uri "/.env"] [unique_id "afb0kKHL7i3v4t7cBXpgcAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 06:53:12
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 02:53:06.087206 2026] [security2:error] [pid 14710:tid 14710] [client 198.23.211.167:5322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.williambarfoot.com"] [uri "/.env.local"] [unique_id "afbw0urAjx3JZv1jytbAdAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-03 06:29:15
(5 months ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 198.23.211.167 (US/United States/198- ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 198.23.211.167 (US/United States/198-23-211-167-host.colocrossing.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-03 06:27:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.211.167 (198-23-211-167-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 02:27:27.455734 2026] [security2:error] [pid 29325:tid 29325] [client 198.23.211.167:27314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.intercite.com"] [uri "/.env"] [unique_id "afbqz9FmXMu_j6etuKvoIgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-05-03 06:15:04
(5 months ago)
tcp/443; AWS dotfile access attempt: "GET /.aws/credentials" @ 2026-05-03T06:06:06Z [proxy]
Web App Attack
๐ซ๐ท
omartin
2026-05-03 06:10:16
(5 months ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-05-03 05:41:06
(5 months ago)
(mod_security) mod_security (id:949110) triggered by 198.23.211.167 (US/United States/198-23-211-167 ...
show more
(mod_security) mod_security (id:949110) triggered by 198.23.211.167 (US/United States/198-23-211-167-host.colocrossing.com): N in the last X secs
show less
Web App Attack