๐ฌ๐ง
Apache
2026-05-15 19:00:21
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.110 (US/United States/-): 5 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.110 (US/United States/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 18:57:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 14:57:46.369497 2026] [security2:error] [pid 28773:tid 28773] [client 208.84.100.110:51688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pluscures.com"] [uri "/.env"] [unique_id "agdsqp6gJVjULtwF4wfsAAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 18:36:32
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 14:36:27.169449 2026] [security2:error] [pid 516:tid 516] [client 208.84.100.110:37282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsdepot.com"] [uri "/.env"] [unique_id "agdnq4nG8NXAyg0M5nmdvwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-15 18:06:21
(2 weeks ago)
Too many Status 40X (16)
Scanning/Probing (14)
Brute-Force
Web App Attack
Anonymous
2026-05-15 18:05:35
(2 weeks ago)
Blocked: Reason='Suspicious traffic score=80 (review-based detection)'; Requests=49
Hacking
๐ง๐ช
cmbplf
2026-05-15 17:45:52
(2 weeks ago)
642 requests with url.path *.git/*
416 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-15 17:43:29
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 208.84.100.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 208.84.100.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 13:43:24.206257 2026] [security2:error] [pid 19171:tid 19171] [client 208.84.100.110:59886] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hamiltonbookings.com"] [uri "/.env"] [unique_id "agdbPBjsbtisWQ_pNtcjCgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-05-15 17:40:55
(2 weeks ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ซ๐ท
Baking333
2026-05-15 17:31:32
(2 weeks ago)
[redacted] 208.84.100.110 - - [15/May/2026:18:31:31 +0100] "GET /backend/.env HTTP/1.1" 302 5293 0/5 ...
show more
[redacted] 208.84.100.110 - - [15/May/2026:18:31:31 +0100] "GET /backend/.env HTTP/1.1" 302 5293 0/56017 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36" [redacted] 208.84.100.110 - - [15/May/2026:18:31:31 +0100] "GET /api/.env HTTP/1.1" 302 5325 0/56685 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-15 17:24:06
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 17:19:20
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 13:19:11.916303 2026] [security2:error] [pid 2414:tid 2414] [client 208.84.100.110:33614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mdsshop.com"] [uri "/.env"] [unique_id "agdVj1IjrVAzP-SHVIozAQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-05-15 17:17:19
(2 weeks ago)
env leak on odypays.org/app/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
Matthew Ping
2026-05-15 17:15:01
(2 weeks ago)
ModSecurity rule 949110 triggered on dedicated. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-05-15 17:13:39
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-15 17:01:56
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack