Anonymous
2026-07-24 04:40:32
(15 hours ago)
20.165.181.42 - - [24/Jul/2026:06:40:31 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macint ...
show more
20.165.181.42 - - [24/Jul/2026:06:40:31 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 03:23:09
(16 hours ago)
(mod_security) mod_security (id:949110) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 23:23:02.820249 2026] [security2:error] [pid 3903580:tid 3903580] [client 20.165.181.42:55347] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "everszuidweg.info"] [uri "/.env"] [unique_id "amLalmYqz5-FF7PhlM8ZVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-24 03:18:56
(16 hours ago)
cloudlinux2 fail2ban: 2026-07-24 05:14:50,772 fail2ban.filter [1816]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-24 05:14:50,772 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 103.214.20.100 - 2026-07-24 05:14:50cloudlinux2 fail2ban: 2026-07-24 05:14:50,555 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 103.214.20.100 - 2026-07-24 05:14:50cloudlinux2 fail2ban: 2026-07-24 05:14:51,000 fail2ban.filter [1816]: INFO [recidive] Found 103.214.20.100 - 2026-07-24 05:14:50cloudlinux2 fail2ban: 2026-07-24 05:14:50,796 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 103.214.20.100 - 2026-07-24 05:14:50cloudlinux2 fail2ban: 2026-07-24 05:14:50,824 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 103.214.20.100 - 2026-07-24 05:14:50cloudlinux2 fail2ban: 2026-07-24 05:14:50,994 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 103.214.20.100cloudlinux2 fail2ban: 2026-07-24 05:14:50,810 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 103.214.20.100 - 2026-07-24 05:14:50cloudlinux2 fail2ban:
show less
Web App Attack
๐ธ๐ช
SkyDancer
2026-07-24 03:13:34
(16 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-24 02:36:43
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 22:36:36.444313 2026] [security2:error] [pid 3372629:tid 3372629] [client 20.165.181.42:62007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "encoreporchfest.info"] [uri "/.env"] [unique_id "amLPtB32-4GTkS-Nm4srzwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-24 01:25:29
(18 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-24 01:23:27
(18 hours ago)
IM360 WAF: Laravel Apps Leaking Secrets exploit attempt MV:androxgh0st
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 00:09:28
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 20:09:21.935739 2026] [security2:error] [pid 3205094:tid 3205094] [client 20.165.181.42:55736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diamenty.info"] [uri "/.env"] [unique_id "amKtMWOWwrTGWP-4wbhKWgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 23:16:29
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 19:16:24.033630 2026] [security2:error] [pid 3642:tid 3642] [client 20.165.181.42:63825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danzadance.info"] [uri "/.env"] [unique_id "amKgyEPmiPpSUMpSmpZ4GgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 23:01:23
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 19:01:15.757863 2026] [security2:error] [pid 1535131:tid 1535131] [client 20.165.181.42:57012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cypraea.info"] [uri "/.env"] [unique_id "amKdO-CKJFo3j7TyDg9-ZAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 20:49:21
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 16:49:14.260273 2026] [security2:error] [pid 3097805:tid 3097805] [client 20.165.181.42:59436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cityslickerstomp.info"] [uri "/.env"] [unique_id "amJ-St56bMghjrB1t6_v8AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 20:19:10
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 16:19:04.343485 2026] [security2:error] [pid 2921869:tid 2921869] [client 20.165.181.42:63971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chassell.info"] [uri "/.env"] [unique_id "amJ3OK55CMtnZLS6ZYEoZAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 18:15:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 14:15:43.509127 2026] [security2:error] [pid 30553:tid 30553] [client 20.165.181.42:65246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "borzoi-pedigree.info"] [uri "/.env"] [unique_id "amJaT5dMZPAvPG7AEy76xwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 17:25:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.165.181.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:25:28.693690 2026] [security2:error] [pid 3319270:tid 3319289] [client 20.165.181.42:54437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bhsclassof68.info"] [uri "/.env"] [unique_id "amJOiOmxHppnfySDtRisbwAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-23 17:03:59
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack