Anonymous
2026-06-10 23:06:04
(2 days ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 21:07:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.29.52.246 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.29.52.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 17:07:40.274398 2026] [security2:error] [pid 4566:tid 4566] [client 20.29.52.246:21652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.17"] [uri "/.env"] [unique_id "ainSHKWc4GLFHlJ0Ow1J7gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-06-10 20:05:00
(2 days ago)
\[Wed Jun 10 22:04:59.047409 2026\] \[:error\] \[pid 28099:tid 139785977566976\] \[client 20.29.52.2 ...
show more
\[Wed Jun 10 22:04:59.047409 2026\] \[:error\] \[pid 28099:tid 139785977566976\] \[client 20.29.52.246:22791\] \[client 20.29.52.246\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 8\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "78.46.187.162"\] \[uri "/.git/HEAD"\] \[unique_id "ainDa1rYMvKgPQqhFFX7egAAAUA"\]
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 19:41:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.29.52.246 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.29.52.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 15:41:28.476089 2026] [security2:error] [pid 4175:tid 4175] [client 20.29.52.246:22428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.155"] [uri "/.git/HEAD"] [unique_id "aim96E3CiKU7qaCzN2qFpQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MaxMeier
2026-06-10 18:38:41
(2 days ago)
20.29.52.246 - - [10/Jun/2026:20:37:39 +0200] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Linu ...
show more
20.29.52.246 - - [10/Jun/2026:20:37:39 +0200] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Mobile Safari/537.36"
20.29.52.246 - - [10/Jun/2026:20:37:41 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
20.29.52.246 - - [10/Jun/2026:20:37:41 +0200] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0"
20.29.52.246 - - [10/Jun/2026:20:37:42 +0200] "GET /.env.local HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
20.29.52.246 - - [10/Jun/2026:20:37:45 +0200] "GET /.env.backup HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
20.29.52.246 - - [10/Jun/2026:20:37:47 +0200] "GET /.env.save HTTP/1.1" 444 0 "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 18:06:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.29.52.246 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.29.52.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 14:06:42.546621 2026] [security2:error] [pid 6343:tid 6343] [client 20.29.52.246:22378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.189"] [uri "/.git/HEAD"] [unique_id "aimnsq25tYxWjroiDv3CBAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-06-10 18:02:50
(2 days ago)
Threat Intelligence via ARMTI, Web Attack: POST /___proxy_subdomain_whm/login/?login_only=1
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-10 17:53:58
(2 days ago)
(mod_security-custom) mod_security (id:210492) triggered by 20.29.52.246 (US/United States/Iowa/Des ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 20.29.52.246 (US/United States/Iowa/Des Moines/-/[AS8075 MICROSOFT-CORP-MSN-AS-BLOCK]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
๐ฉ๐ช
maxpower
2026-06-10 17:41:03
(2 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.29.52.246 (US/United States/-): 2 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.29.52.246 (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.29.52.246 - - [10/Jun/2026:19:40:57 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" host=51.89.2.99
20.29.52.246 - - [10/Jun/2026:19:40:57 +0200] "GET /.aws/credentials HTTP/1.1" 404 10386 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "-" host=51.89.2.99
show less
Port Scan
๐บ๐ธ
lnklnx
2026-06-10 17:36:49
(2 days ago)
www.lnklnx.com:80 20.29.52.246 - - [10/Jun/2026:12:36:46 -0500] "GET /.git/HEAD HTTP/1.1" 301 591 "- ...
show more
www.lnklnx.com:80 20.29.52.246 - - [10/Jun/2026:12:36:46 -0500] "GET /.git/HEAD HTTP/1.1" 301 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
...
show less
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2026-06-10 17:01:46
(2 days ago)
UFW:High-frequency access to unused ports
Port Scan