🇸🇪
vaia.cloud
2026-09-12 20:25:01
(2 hours ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇫🇷
Sklurk
2026-09-09 06:46:11
(3 days ago)
Web App Attack
Web App Attack
🇺🇸
drewf.ink
2026-09-02 00:27:46
(1 week ago)
[00:27] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[00:27] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
🇺🇸
drewf.ink
2026-09-01 10:58:05
(1 week ago)
[10:58] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[10:58] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
🇺🇸
drewf.ink
2026-08-30 02:56:26
(1 week ago)
[02:56] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[02:56] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
🇫🇷
Sklurk
2026-08-05 01:58:36
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-18 02:01:25
(1 month ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-02-10 03:27:49
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:27:42.901507 2026] [security2:error] [pid 7474:tid 7474] [client 209.50.168.144:47117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirklandplumbing.ca"] [uri "/admin/.env"] [unique_id "aYqlrmGLpeFhXwfC5nKm8wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
myagent.site
2026-02-10 01:16:29
(7 months ago)
Blocking for trying to access an exploit file: /.env.save
Hacking
🇺🇸
TPI-Abuse
2026-02-10 00:34:22
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:34:12.696069 2026] [security2:error] [pid 18342:tid 18342] [client 209.50.168.144:58521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevinfranz.com"] [uri "/.env.staging"] [unique_id "aYp9BIpPktgJ9dcUIjp4fwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 22:55:56
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:55:50.370057 2026] [security2:error] [pid 1570:tid 1600] [client 209.50.168.144:61489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howiek.com"] [uri "/dev/.git/config"] [unique_id "aYpl9neVpx3S5SN-NSqeMQAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 22:23:18
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:23:13.034827 2026] [security2:error] [pid 1537256:tid 1537256] [client 209.50.168.144:55517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotwheelguide.com"] [uri "/admin/.env"] [unique_id "aYpeUcBkxLMHw-Z5LeLYigAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 22:02:06
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:01:56.251434 2026] [security2:error] [pid 804:tid 804] [client 209.50.168.144:61503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katharinanitzpon.com"] [uri "/new/.git/config"] [unique_id "aYpZVH8UY4V6kmBW7w2KzAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-27 20:51:13
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 15:51:06.789386 2025] [security2:error] [pid 18142:tid 18142] [client 209.50.168.144:56215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "customhumanrobots.com"] [uri "/.git/HEAD"] [unique_id "aSi5usq3SpYX6i4fffYL0QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 11:27:01
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.168.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:26:55.206009 2025] [security2:error] [pid 7670:tid 7670] [client 209.50.168.144:36747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jboomergrenier.com"] [uri "/.env"] [unique_id "aSbj_yHVGauxPt36tY_yngAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack