๐ซ๐ท
Sklurk
2026-08-01 00:40:28
(1 day ago)
Web App Attack
Web App Attack
๐ฉ๐ช
Trueforce Threat Report
2026-06-25 05:55:16
(1 month ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-06-20 08:55:57
(1 month ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-26 03:15:57
(8 months ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:15:14
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.250 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:15:08.822763 2025] [security2:error] [pid 3296143:tid 3296160] [client 216.26.239.250:35025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pershia.net"] [uri "/.git/HEAD"] [unique_id "aSZGjH8uvS_75eRGAWOI5wAAAY8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:33:07
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.250 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:32:59.084084 2025] [security2:error] [pid 17999:tid 17999] [client 216.26.239.250:39479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.blacksheepoffroad.com"] [uri "/.env"] [unique_id "aSQYO5L1WeHDDHt5iEYS6AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:14:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.239.250 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.239.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:14:13.695042 2025] [security2:error] [pid 31463:tid 31463] [client 216.26.239.250:22563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.momokuwait.gulftelecom.com"] [uri "/.env"] [unique_id "aSQT1XVrgrQxp_RpD4pJDgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 00:56:49
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 216.26.239.250 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 216.26.239.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 09 19:56:43.873233 2025] [security2:error] [pid 12982:tid 12982] [client 216.26.239.250:18465] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nlc-calumet.org.dhsgrad.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nlc-calumet.org.dhsgrad.net"] [uri "/s3cmd.ini"] [unique_id "aRE4SzXUhzItBZrUjkmxegAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-01 23:32:00
(9 months ago)
Unauthorized connection attempt
Brute-Force
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-10-28 12:23:03
(9 months ago)
WP Login Scan Activities
Web App Attack