๐ณ๐ฑ
debestelapp
2026-05-14 13:45:08
(2 weeks ago)
Web App Attack
๐ง๐ช
cmbplf
2026-05-14 13:41:45
(2 weeks ago)
480 requests with url.path *.env
131 requests with url.path *.aws/*
Brute-Force
Bad Web Bot
Anonymous
2026-05-14 13:17:45
(2 weeks ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2026-05-14 13:10:06
(2 weeks ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-14 12:59:21
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 08:59:15.680114 2026] [security2:error] [pid 16928:tid 16928] [client 208.84.100.208:51306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stinnetthomeinspection.com"] [uri "/.env.production.copy"] [unique_id "agXHI_tzqMz4BJnl4uezBgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sc user
2026-05-14 12:35:24
(2 weeks ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฉ๐ช
Petros Stefanakis
2026-05-14 12:23:18
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 208.84.100.208 (US/United States/-)
SQL Injection
Anonymous
2026-05-14 12:05:36
(2 weeks ago)
Blocked: Reason='Suspicious traffic score=80 (review-based detection)'; Requests=55
Hacking
๐ณ๐ฑ
e.fierstra
2026-05-14 11:59:42
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ง๐ท
mubusys.com
2026-05-14 11:47:09
(2 weeks ago)
208.84.100.208 - - [14/May/2026:08:47:01 -0300] "GET /secrets.json HTTP/1.1" 403 1170 "-" "Mozilla/5 ...
show more
208.84.100.208 - - [14/May/2026:08:47:01 -0300] "GET /secrets.json HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0" "-"
208.84.100.208 - - [14/May/2026:08:47:01 -0300] "GET /.env HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36" "-"
208.84.100.208 - - [14/May/2026:08:47:03 -0300] "GET /app/.env HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36" "-"
208.84.100.208 - - [14/May/2026:08:47:03 -0300] "GET /service-account.json HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36" "-"
208.84.100.208 - - [14/May/2026:08:47:03 -0300] "GET /backend/.env HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.0) Gecko/20100101
show less
Port Scan
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-05-14 11:29:23
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-05-14 11:05:14
(2 weeks ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐ซ๐ท
dwmp
2026-05-14 11:04:08
(2 weeks ago)
[14/May/2026:13:04:07.283621 +0200] agWsJwLhdMo9A3JDFfoWtgAAAVY 208.84.100.208 45182 38.242.227.117 ...
show more
[14/May/2026:13:04:07.283621 +0200] agWsJwLhdMo9A3JDFfoWtgAAAVY 208.84.100.208 45182 38.242.227.117 7081
[14/May/2026:13:04:07.625952 +0200] agWsJwLhdMo9A3JDFfoWtwAAAVM 208.84.100.208 45184 38.242.227.117 7081
[14/May/2026:13:04:07.691543 +0200] agWsJwLhdMo9A3JDFfoWuQAAAUE 208.84.100.208 45188 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐ฉ๐ช
Sรฉfora Srl
2026-05-14 11:02:31
(2 weeks ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 11:02:08
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 07:02:00.660797 2026] [security2:error] [pid 25159:tid 25159] [client 208.84.100.208:15512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-hong-kong.com"] [uri "/.env.orig"] [unique_id "agWrqC0jyLS0sXq-K-ihBwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack