๐ฉ๐ช
conseilgouz
2026-10-03 09:10:49
(1 hour ago)
doe-17 : Block hidden directories=>/.env(/)
Hacking
๐ฉ๐ช
TheDjRider
2026-10-03 08:34:49
(2 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-10-03T08:34:46.920967028Z. Context: http_status=200
show less
Web App Attack
๐ซ๐ท
regishoussin
2026-10-03 06:18:12
(4 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-03 06:18 UTC.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 05:43:06
(4 hours ago)
http scanning for .env files
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 05:29:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:29:19.045683 2026] [security2:error] [pid 3555:tid 3745] [client 2001:ba0:200:c300::1:65434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eastcentralalgas.com"] [uri "/.env"] [unique_id "asCSr5M2bKfvxn-0OndHUAAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-10-03 04:22:14
(6 hours ago)
ece-17 : Block hidden directories=>/.env(/)
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-03 02:30:18
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:30:10.600971 2026] [security2:error] [pid 1241:tid 1241] [client 2001:ba0:200:c300::1:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hondabvi.com"] [uri "/.env"] [unique_id "asBosrJuy25XqHW9VSgRfQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:36:31
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:36:24.413799 2026] [security2:error] [pid 19866:tid 19866] [client 2001:ba0:200:c300::1:58775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentweakley.com"] [uri "/.env"] [unique_id "ar_5qLoFnhWSzjh8G5cnPgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-10-02 18:32:36
(16 hours ago)
vee-17 : Block hidden directories=>/.env(/)
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 18:04:19
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:04:14.711965 2026] [security2:error] [pid 27847:tid 27847] [client 2001:ba0:200:c300::1:51395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nemoscientific.com"] [uri "/.env"] [unique_id "ar_yHoxNpiWEnOsA4JfuQgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:14:58
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:14:50.736519 2026] [security2:error] [pid 4897:tid 4920] [client 2001:ba0:200:c300::1:65242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goawaybirding.com"] [uri "/.env"] [unique_id "ar_mivvQ4AZo86UL8p8kkAAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:45:06
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:44:58.221884 2026] [security2:error] [pid 26103:tid 26103] [client 2001:ba0:200:c300::1:58422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "affordablecontractingwvreviews.com"] [uri "/.env"] [unique_id "ar_fihHccBgIlusZPK_mSQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:48:19
(19 hours ago)
(mod_security) mod_security (id:949110) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:949110) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:48:12.189659 2026] [security2:error] [pid 17917:tid 17917] [client 2001:ba0:200:c300::1:62492] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "jackyoung.studio"] [uri "/.env"] [unique_id "ar_ELP1JSsZ1uk6bqvuIogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:04:44
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:04:36.891730 2026] [security2:error] [pid 14170:tid 14170] [client 2001:ba0:200:c300::1:50465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thespotfurniture.com"] [uri "/.env"] [unique_id "ar-d1M7w29fxm_d_rwvl-QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:17:55
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:ba0:200:c300::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:17:50.468852 2026] [security2:error] [pid 14522:tid 14522] [client 2001:ba0:200:c300::1:50831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carinsteen.com"] [uri "/.env"] [unique_id "ar-S3vWounf7YXTU1riS_wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack