๐ฉ๐ช
ramazan
2026-08-18 18:50:52
(3 weeks ago)
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.git/ /.git/hooks/post-commit.sample /.git/hooks/post-rec ...
show more
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.git/ /.git/hooks/post-commit.sample /.git/hooks/post-receive.sample /.git/info/refs /.git/logs/refs/heads/development
show less
Web App Attack
Hacking
๐ณ๐ฑ
jjnxpct
2026-03-12 04:48:38
(5 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: / (Rule ID: 920340) - Content-Type header missing from request with non-zero Content-Length
show less
Web App Attack
๐บ๐ธ
gamabe
2026-03-11 11:20:10
(6 months ago)
Detected crowdsecurity/http-cve-probing attack pattern. Reported by CrowdSec IDS.
Port Scan
๐ฉ๐ช
Skyrider
2026-03-11 11:12:36
(6 months ago)
crowdsecurity/CVE-2017-9841
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-11 08:25:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.38.80.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.80.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 04:25:53.086929 2026] [security2:error] [pid 15664:tid 15664] [client 209.38.80.3:29256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "procurement.ic1.biz"] [uri "/.env"] [unique_id "abEnEY9tGdsk6XdJsK6gDwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-03-11 07:57:46
(6 months ago)
Scanning for exploits - /.env
Web App Attack
๐จ๐ญ
TheCoon
2026-03-11 07:45:01
(6 months ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฎ๐ฉ
Burayot
2026-03-11 07:32:51
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 209.38.80.3 (AU/Australia/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 209.38.80.3 (AU/Australia/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-03-11 07:23:54
(6 months ago)
209.38.80.3 - - [11/Mar/2026:09:23:40 +0200] "GET /.env HTTP/1.1" 404 3090 "-" "Mozilla/5.0 (Windows ...
show more
209.38.80.3 - - [11/Mar/2026:09:23:40 +0200] "GET /.env HTTP/1.1" 404 3090 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
209.38.80.3 - - [11/Mar/2026:09:23:53 +0200] "GET /.env HTTP/1.1" 404 310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 07:16:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.38.80.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.80.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 03:16:51.907959 2026] [security2:error] [pid 9484:tid 9484] [client 209.38.80.3:25560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "probiopharmaceutical.com"] [uri "/.env"] [unique_id "abEW48rBeCOV3-y-g6Q6qAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 06:54:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.38.80.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.80.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 02:54:25.065561 2026] [security2:error] [pid 16214:tid 16214] [client 209.38.80.3:31704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "probeanalysis.com.afjm.net"] [uri "/.env"] [unique_id "abERoWMGbcm4M9h92xM65wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
helix
2026-03-11 06:25:20
(6 months ago)
Automated report: SSH brute force detected. This IP exceeded the allowed number of failed login atte ...
show more
Automated report: SSH brute force detected. This IP exceeded the allowed number of failed login attempts (3 attempts).
show less
Brute-Force
SSH
๐ฉ๐ช
LRob
2026-03-11 06:15:08
(6 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
Anonymous
2026-03-11 06:05:32
(6 months ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=17
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-11 05:53:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.38.80.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.80.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 01:53:37.474375 2026] [security2:error] [pid 13087:tid 13087] [client 209.38.80.3:60492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pro.handyrehab.com"] [uri "/.env"] [unique_id "abEDYVuvSQjj4fCUnh53ewAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack